Security researchers at McAfee say a malicious campaign dubbed “WeedHack” has been targeting Minecraft players—and it’s getting more aggressive, not less. In June, McAfee observed WeedHack operations using fake “game client” pages to lure victims. The twist: when the original command-and-control (C2) channel was disclosed and then went dead, attackers didn’t stop. Instead, they pivoted—repackaging delivery and continuing distribution via community platforms. McAfee reports WeedHack has been active since January 2026, infecting 116,000+ players so far. It’s essentially a “malware-as-a-service” (MaaS) operation: criminals provide the infrastructure so less technical actors can replicate the attack chain. After infection, WeedHack aims to steal passwords and browser data, then harvest Minecraft and Discord account information, and finally target crypto wallet contents to monetize the breach. Even after initial disclosure, intel suggests at least a dozen additional malicious sites kept pushing samples. Attackers also used SEO manipulation and lookalike landing pages that appear to link to trusted resources (including seemingly legitimate GitHub repositories). What you can do: verify domains before installing “client” tools; review browser logins, Discord access, and wallet permissions regularly. #CyberSecurity #Malware #Minecraft #Phishing #Discord #CryptoScams
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论