Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Weedhack Malware Targets Gamers via Fake Minecraft Sites

Weedhack Malware Targets Gamers via Fake Minecraft Sites

Posted on August 25, 2026 By CWS

Cybersecurity experts have recently uncovered a concerning trend of malware distribution targeting gamers, specifically through fake Minecraft clients. The malicious software, known as Weedhack, is being spread by websites that closely mimic legitimate Minecraft-related platforms.

Malware Distribution Through Fake Gaming Sites

According to McAfee Labs, over 6,300 attempts have been identified and blocked as users tried to access these harmful websites. These sites are crafted to resemble authentic gaming resources, complete with branding and links that appear credible, including connections to real GitHub repositories.

One such fraudulent site was developed using Lovable, an AI-powered tool, underscoring how easily attackers can create convincing malicious websites. This tactic not only deceives users but also utilizes SEO poisoning to redirect traffic to the harmful domains.

Techniques and Platforms Used in Distribution

Weedhack employs a multi-stage attack strategy, culminating in the execution of JAR payloads designed to harvest system data, alter Microsoft Defender settings, and exfiltrate sensitive information from the infected host.

McAfee Labs researcher Aayush Tyagi noted that nearly half of the malicious URLs originate from Discord links. Other platforms such as MediaFire and GitHub are also used, demonstrating how attackers leverage popular services to propagate the malware.

Fake Domains and SEO Manipulation

Several domains have been identified as part of this malware campaign, including glazed-client[.]com and radium-client[.]com, which mimic legitimate Minecraft clients. These sites often appear prominently in search engine results, outpacing genuine sources through SEO manipulation.

The real versions of these clients are hosted on platforms like GitHub and Modrinth, but attackers have crafted fake sites that use SEO poisoning to mislead users into downloading malware-laden clients instead.

Preventive Measures and Awareness

To mitigate the risk of falling victim to such threats, users are advised to ensure their devices are updated regularly, rely on trusted sources, and thoroughly scan files before opening them. Additionally, caution should be exercised when any software requests disabling security features during installation.

This method of using SEO poisoning to distribute malware is not unprecedented. Similar campaigns have previously targeted popular open-source and freeware projects, distributing malware like Remus Stealer and other malicious frameworks.

The Hacker News Tags:AI website builder, Cybersecurity, fake websites, gaming security, malicious URLs, Malware, McAfee Labs, Minecraft, SEO poisoning, Weedhack

Post navigation

Previous Post: Mysterious Ox Alpha AI Offers Free Tokens to Coders
Next Post: Hackers Mimic ReliaQuest Staff for Credential Theft

Related Posts

New Browser Security Report Reveals Emerging Threats for Enterprises New Browser Security Report Reveals Emerging Threats for Enterprises The Hacker News
UAT-10362: LucidRook Malware Targets Taiwanese NGOs UAT-10362: LucidRook Malware Targets Taiwanese NGOs The Hacker News
Critical Cisco Flaw Exploited, Causes Remote DoS Risks Critical Cisco Flaw Exploited, Causes Remote DoS Risks The Hacker News
Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection Hackers Weaponize Windows Hyper-V to Hide Linux VM and Evade EDR Detection The Hacker News
Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances The Hacker News
Why Traditional DLP Solutions Fail in the Browser Era Why Traditional DLP Solutions Fail in the Browser Era The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Mimic ReliaQuest Staff for Credential Theft
  • Weedhack Malware Targets Gamers via Fake Minecraft Sites
  • Mysterious Ox Alpha AI Offers Free Tokens to Coders
  • Hackers Exploit Search Engines with Phishing Pages
  • Microsoft Teams Introduces Bot-Blocking Policy for Meetings

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Mimic ReliaQuest Staff for Credential Theft
  • Weedhack Malware Targets Gamers via Fake Minecraft Sites
  • Mysterious Ox Alpha AI Offers Free Tokens to Coders
  • Hackers Exploit Search Engines with Phishing Pages
  • Microsoft Teams Introduces Bot-Blocking Policy for Meetings

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark