glazed-client landing page
At a Glance
| Malware family | WeedHack (Malware-as-a-Service infostealer) |
| Threat actor | Unnamed MaaS operators and customers (not publicly attributed) |
| Targets / victims | Minecraft gamers; over 116,464 infected per prior reporting |
| Delivery vector | Fake client sites, SEO poisoning, Discord, MediaFire, GitHub |
| Key capabilities | Trojanized JAR downloads impersonating Minecraft clients |
| Source | McAfee Labs research report |
TL;DR
WeedHack malware is still spreading, even after McAfee disrupted its main server. The operators now push trojanized Minecraft clients through fake websites and Minecraft SEO poisoning. McAfee WebAdvisor blocked more than 6,300 access attempts in the past month alone.
What Happened
McAfee Labs first exposed WeedHack in early July 2026. That report knocked out the campaign’s command-and-control server and its dashboard. The threat did not stop, though. Researchers found the operators simply changed tactics.
WeedHack malware now flows through many active websites that impersonate real Minecraft tools. McAfee reports that the threat “has continued to evolve even after its original command-and-control infrastructure was disrupted.”
Earlier reporting counted more than 116,464 infected gamers. That scale came largely from search-engine tricks. This is Malware-as-a-Service, sold cheaply with tutorials that teach buyers how to target gaming software.
Delivery: Fake Clients and Poisoned Search Results
The lures look convincing. Attackers clone real client sites down to the branding, feature lists, FAQs, install guides, and developer credits. Many even link to the genuine GitHub repository to build trust.
Minecraft SEO poisoning puts these fakes at the top of search results. In one case, the top two Google results for a popular client led to WeedHack sites. As McAfee put it, this shows how “SEO poisoning can put malicious downloads directly in gamers’ paths.”
Common Impersonation Targets
Researchers named several spoofed clients. Fake pages copied Glazed Client, Radium, SeedCrackerX, Xenon Client, Nova Client, and Meteor Client. One site even offered a paid tool for free to bait users. Every download link delivered WeedHack instead.
Infection Chain and Distribution Channels
The infection starts with a single click. A gamer downloads what looks like a real client JAR file. That file carries the WeedHack payload and infects the system on run.
The operators lean on trusted platforms to host files. Nearly half of the malicious URLs were Discord links, at 49.6 percent. MediaFire followed at 23.4 percent, then GitHub at 8.2 percent and Dropbox at 4.6 percent. Attackers also abused community sites like Planet Minecraft and EndMods.
AI-Built Malicious Sites
One finding stands out. Researchers spotted a malicious site built with an AI-powered website builder. That tool lets operators launch convincing new domains fast. McAfee warns these tools “can make it faster and easier for scammers to create convincing websites.”
Attribution
McAfee has not publicly named the people behind WeedHack. The report describes it as a Malware-as-a-Service campaign with many customers. So attribution stays at the campaign level, not a named group. Treat any single-operator claim as unconfirmed.
Defense and Detection Guidance
Protection must start before the download lands. First, download clients only from official sources you can verify. Check the exact domain spelling, since fakes often add or drop a single letter.
Do not trust free copies of paid tools. Be wary of client links shared through Discord, MediaFire, or random forums. Use web protection that flags dangerous sites and downloads early. As McAfee notes, protection “needs to start before a malicious download ever reaches your device.”
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!