A new wave of malware targeting Minecraft players has been uncovered by cybersecurity firm McAfee. The threat, dubbed WeedHack, disguises itself as unofficial game modifications to trick users into downloading malicious software. According to McAfee, the malware campaign has recorded more than 116,000 infections since January 2026.

Cybersecurity firm McAfee uncovered a campaign distributing malicious software disguised as third-party game modifications to steal user credentials and access webcams.
The malware specifically targets players who download mods from unofficial websites rather than official platforms. Attackers host these modified clients on third-party sites and use YouTube videos to distribute links directly to Minecraft communities. The primary targets include popular unofficial modifications like Meteor Client and Radium Client, which lack official developer oversight or secure distribution channels.
WeedHack performs several malicious actions once installed on a victim's computer. It steals login credentials, hijacks game accounts, records keystrokes, and gains access to webcams and screen content. The premium version of the malware offers attackers remote shell access and live monitoring capabilities for both screens and cameras.
The campaign exploits the lack of official support channels for unofficial mod developers. Without verified websites or direct contact methods for these creators, users have no reliable way to verify the authenticity of downloaded files. This gap allows threat actors to easily distribute compromised versions that appear legitimate to unsuspecting players.
McAfee reports this infection count based on their internal monitoring systems, though they do not provide an independent audit trail to verify the exact number of affected devices. This reported total reflects recorded infection events, which may not correspond one-to-one with distinct compromised devices or individual users.
Source: PCGAMESN




Discussion
0 comments