McAfee Labs discovered a Malware-as-a-Service campaign called WeedHack targeting Minecraft players since January 2026. The attack infects over 116,464 systems worldwide and adds roughly 2,000 to 3,000 new infections each day. Attackers distribute the malware through fake mods, clients, and utility tools linked from SEO-poisoned YouTube videos.
WeedHack campaign infects systems through fake mods and SEO poisoned YouTube links
The campaign uses two dedicated YouTube channels and multiple demonstration videos to lure viewers into clicking malicious links. These links redirect users to URLs that host over 240 distinct distribution points for the attack. McAfee researcher Aayush Tyagi confirmed the scale of the operation in an official blog post detailing the findings.
WeedHack steals session IDs, browser passwords, cookies, Discord and Steam credentials, crypto wallet data, system information, and screenshots from infected machines. The malware employs a technique called EtherHiding to disable Windows Defender before collecting this data. Premium tiers of the service grant attackers live webcam access, keystroke logging, remote control of inputs, and command-line access.
The malware-as-a-service model operates openly with a free tier available alongside paid plans starting at $5 per month or $24.99 for lifetime access. McAfee researchers infiltrated associated Telegram channels and reported that the service primarily targets teenagers and young adults. These users often deploy the remote access capabilities to threaten, harass, and monitor victims within their own age group.
The campaign represents a significant intersection of gaming culture and cyberbullying threats. Attackers exploit the popularity of Minecraft mods and clients to bypass security measures and reach a broad audience. The widespread infection rate highlights how easily malicious code can spread through unverified third-party game modifications.



Discussion
0 comments
Log in to join the thread with a thoughtful take, question, or correction.