Over 116,000 Mincraft systems infected in WeedHack malware campaign
A large-scale malware campaign, dubbed WeedHack, has infected over 116,000 Minecraft systems since January, primarily through malicious mods and clients promoted via YouTube and SEO poisoning. The malware operates as a MaaS infostealer, stealing credentials and data from compromised systems, and offers both free and premium tiers with varying levels of access and control. This highlights the risks associated with downloading software from unofficial sources and the evolving tactics of cybercriminals.
The WeedHack campaign leverages Minecraft-related tools and clients, targeting players who utilize them. The malware is distributed through malicious mods, clients, cheats, and utilities promoted on YouTube and through SEO poisoning, often utilizing keywords related to popular Minecraft clients like Meteor Client and Wurst Client. McAfee’s telemetry data indicates a significant daily infection rate, with the majority of victims located in the United States, Germany, India, and the UK. The campaign utilizes over 240 distribution URLs and 3,820 unique JAR files, demonstrating the scale of the operation. The attacker employs deceptive tactics, such as creating fake websites that mimic legitimate repositories and using authentic-sounding voice-over narration in YouTube videos to build trust.
The WeedHack operation functions as a Malware-as-a-Service (MaaS), offering a dashboard to customers to view stolen data and manage compromised systems. The free tier focuses on stealing session IDs, cookies, and credentials from various platforms including browsers, cryptocurrency wallets, and messaging apps. A premium tier provides enhanced capabilities, including remote control access, webcam access, and keylogging. McAfee reports that many users are teenagers or young adults utilizing the remote access tools for harassment.
This incident underscores the importance of caution when downloading software, particularly from unofficial sources. Players should prioritize downloading mods and clients from official project sources, verifying download links, and treating JAR files hosted on dubious sites with extreme caution. The campaign also highlights the increasing sophistication of cybercriminals and their ability to exploit popular gaming communities.