logo

Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown

ID: c44be9b3-8b21-533f-8e85-ac1b74ee74b0

STIX ID: report--c44be9b3-8b21-533f-8e85-ac1b74ee74b0

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Pierluigi Paganini

...
...

McAfee’s follow-up on the WeedHack Malware-as-a-Service campaign shows that even after its C2 infrastructure was disrupted the operation continues to spread an infostealer through convincing fake Minecraft client sites, SEO poisoning, Discord channels and file-hosting links; the malware has logged over 116,000 infections, steals browser credentials and crypto wallet data, and uses techniques like EtherHiding to maintain resilience.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.