Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
A new malware campaign, dubbed Weedhack, is targeting Minecraft players through YouTube and malicious websites, distributing a MaaS (Malware-as-a-Service) tool. The campaign, active since January 2026, utilizes SEO poisoning and impersonates Minecraft clients to infect users, offering both free and premium tiers of functionality including credential theft and remote access. Simultaneously, McAfee Labs has identified a large-scale CountLoader campaign impacting over 86,000 machines, primarily through cracked software distribution and USB drives, deploying payloads like Cobalt Strike and various RATs.
The Weedhack campaign, developed by McAfee Labs, leverages YouTube and malicious websites to infect Minecraft players. The malware, delivered via a malicious JAR file named "DonutDupe.jar", utilizes techniques like EtherHiding to communicate with a command-and-control server. This server allows operators to monitor compromised systems, create custom payloads targeting Minecraft versions 1.21.0 to 1.21.11, and inject the malware into legitimate Minecraft mods. The campaign’s free tier offers infostealing capabilities targeting browser data, cryptocurrency wallets, and credentials, while the premium tier expands remote access features like webcam access and keylogging. Notably, the campaign has been linked to cyberbullying activities, with attackers using the malware to threaten and monitor victims, sharing recordings on the Telegram channel.
Concurrent with the Weedhack campaign, McAfee Labs has uncovered a significant CountLoader campaign impacting over 86,000 machines. This campaign utilizes a JavaScript loader distributed through cracked software sites, deploying payloads such as Cobalt Strike, AdaptixC2, PureHVNC RAT, Amatera Stealer, and PureMiner. The infection vector involves executing an EXE file, which then launches a PowerShell command to download and execute the CountLoader loader via ‘mshta.exe’. McAfee Labs successfully sinkholed the malware communication infrastructure by registering a fake C2 domain.
