Overview
- Industry researchers say WeedHack’s command-and-control dashboard was disrupted but dozens of lookalike client sites and hosting accounts remain active and still deliver the malware.
- McAfee WebAdvisor blocked more than 6,300 attempts to reach active malicious domains in the past month, showing ongoing user exposure to the campaign.
- Attackers use SEO poisoning so bogus sites appear at the top of search results and distribute downloads through trusted services such as Discord, MediaFire, GitHub, Planet Minecraft and EndMods.
- WeedHack is sold as a Malware-as-a-Service that steals browser cookies, passwords and crypto wallet data and uses techniques like EtherHiding to fetch operator servers from the Ethereum chain.
- Researchers urge players to download only from official GitHub or trusted platforms such as Modrinth and CurseForge, keep security software on and scan files before installing them.