Warning: WeedHack Malware Hidden in Minecraft Add-ons Imitates Legitimate Websites to Steal Data

Views: 43 views

463/69 Wednesday, August 26, 2026

Cybersecurity researchers have detected the spread of WeedHack malware targeting gamers. Threat actors created fake websites impersonating providers of Minecraft add-ons or clients. Reports indicate that access to these malicious websites has already been detected and blocked more than 6,000 times. The attackers used search engine optimization poisoning, or SEO poisoning, to make the fake websites appear among the top results on major search engines, causing general users to trust them and unknowingly download malware onto their computers.

In this attack, the threat actors designed the websites to closely resemble the original projects, including the use of logos, feature descriptions, and seemingly credible references. Researchers found that AI tools were used to generate the websites, reducing development time and increasing realism. In addition to fake websites, malicious links were also distributed through platforms such as Discord, file-hosting services such as MediaFire, and some legitimate game add-on distribution platforms. Once users downloaded and installed the files, the system initiated a multi-stage attack that ultimately deployed a JAR payload. The malware is capable of collecting system information, adding exclusions to security tools, and stealing sensitive user data.

To reduce the risk of infection, users should verify that software is downloaded from official sources and should not rely solely on search engine rankings. They should also avoid downloading files from links shared in chat channels where the source cannot be verified, scan files before opening them, and keep operating systems up to date. Most importantly, users should exercise extreme caution if any program or software asks them to disable security protections on their device before installation.

Source: https://thehackernews.com/2026/08/weedhack-malware-spreads-via-fake.html