Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Weedhack Malware Targets Minecraft Players via YouTube

Weedhack Malware Targets Minecraft Players via YouTube

Posted on June 3, 2026 By CWS

In a concerning development for cybersecurity, researchers have detected a new campaign aimed at Minecraft enthusiasts through YouTube. This campaign, identified as ‘Weedhack’ by McAfee Labs, involves malware-as-a-service (MaaS) that exploits Minecraft mods to gain control over target systems.

Weedhack: A New Threat to Gamers

Active since January 2026, Weedhack impersonates Minecraft clients and modifications to deceive users. The campaign employs SEO poisoning techniques and YouTube videos to drive traffic to malicious URLs. McAfee Labs has identified 3820 unique malicious JAR files and over 240 URLs distributing this malware.

Aayush Tyagi, a security researcher, highlighted the use of YouTube channels and videos that showcase Minecraft Mods and Clients. These videos direct viewers to dangerous URLs, expanding the campaign’s reach. The malware’s central hub, ‘weedhack[.]to,’ provides an enterprise-level dashboard where criminals can monitor stolen data and manage compromised systems.

Technical Details of the Attack

The attack initiates with a malicious JAR file named ‘DonutDupe.jar,’ which is downloaded from compromised websites. This file uses a technique called EtherHiding, leveraging the Ethereum blockchain to access command-and-control (C2) server details. The subsequent stages involve the malware contacting the C2 server to download additional payloads, each with specific malicious functions.

The malware’s distribution strategy includes leveraging a Telegram channel with over 850 members. This channel advertises the malware and provides support, with the tool available in free and premium versions. The free version targets Minecraft session IDs and harvests data from web browsers and cryptocurrency wallets. The premium tier, starting at $4.99 per month, offers enhanced remote access functionalities.

CountLoader and Cryptocurrency Miners

Alongside Weedhack, McAfee Labs has disclosed a widespread campaign involving CountLoader, a JavaScript loader distributed through cracked software sites. This campaign has compromised approximately 86,000 machines, with significant infections in India and Southeast Asia. The loader facilitates the deployment of various malicious payloads, including a cryptocurrency clipper that manipulates clipboard content to redirect transactions.

Furthermore, illegal streaming sites have been used to spread a cryptocurrency miner disguised as a video player plugin update. This miner employs DLL side-loading techniques to execute its operations stealthily, maximizing runtime by disabling system defenses.

These findings underscore the evolving tactics used by cybercriminals to exploit unsuspecting users. The campaigns’ ability to utilize accessible platforms like YouTube and pirated content sites highlights the persistent threats in the digital landscape.

As the situation develops, it is crucial for users to remain vigilant and implement robust security measures to safeguard against these sophisticated cyber threats.

The Hacker News Tags:CountLoader, crypto clipper, cryptocurrency miner, Cybersecurity, malware-as-a-service, Minecraft malware, pirated content, SEO poisoning, Weedhack, YouTube

Post navigation

Previous Post: Critical GitHub Token Flaw Risks User Security
Next Post: HTTP/2 Bomb Exploit Threatens Major Web Servers

Related Posts

New React RSC Vulnerabilities Enable DoS and Source Code Exposure New React RSC Vulnerabilities Enable DoS and Source Code Exposure The Hacker News
Cybersecurity Threats 2026: Key Insights and Alerts Cybersecurity Threats 2026: Key Insights and Alerts The Hacker News
Unveiling Cyber Deception: Lessons from Art Forgery Unveiling Cyber Deception: Lessons from Art Forgery The Hacker News
Russia-Linked Hackers Target Tajikistan Government with Weaponized Word Documents Russia-Linked Hackers Target Tajikistan Government with Weaponized Word Documents The Hacker News
New Self-Spreading Malware Infects Docker Containers to Mine Dero Cryptocurrency New Self-Spreading Malware Infects Docker Containers to Mine Dero Cryptocurrency The Hacker News
Critical Flaw in Palo Alto PAN-OS Allows Remote Code Execution Critical Flaw in Palo Alto PAN-OS Allows Remote Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical Linux Kernel Vulnerability Exploitation Alert
  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint
  • Critical CRLF Vulnerability in Laravel Threatens Email Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical Linux Kernel Vulnerability Exploitation Alert
  • Minecraft Malware Spread through YouTube and SEO Tactics
  • Cyber Attack Exposes Global Stock Exchange Data
  • Understand Your Network from an Attacker’s Viewpoint
  • Critical CRLF Vulnerability in Laravel Threatens Email Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark