WeedHack operators pivoted to Discord, MediaFire and fake reseller sites. Researchers logged over 6300 blocked attempts in the past month alone as players continue chasing cracked clients and cheats.

Minecraft players hunting for unofficial clients, mods or cheats are still walking into malware traps. According to researchers the WeedHack operation is alive and well despite law enforcement and security firms taking down its core infrastructure in July.
The malware-as-a-service package gives attackers remote access to infected machines, letting them steal Minecraft accounts, Discord tokens, browser passwords, crypto wallets and screenshots. Premium versions of the tool were reportedly sold for as little as five dollars a month.
Distribution Shift After Takedown
- Discord accounted for 49.6 percent of links
- MediaFire followed at 23.4 percent
- GitHub 8.2 percent and Dropbox 4.6 percent
- Remaining links pointed to fake Minecraft reseller sites offering paid tools for free
McAfee WebAdvisor blocked more than 6300 attempts to reach these malicious destinations in the past month. The campaign originally used SEO poisoning to rank fake download pages for popular clients. Even though the primary C2 server is gone the attackers simply moved the payload hosting elsewhere.
The operation has been running since at least January 2026 and was adding two to three thousand new victims daily at its peak. Over 3800 distinct malicious files and 240 malicious URLs have been catalogued so far. Minecraft accounts are just the start. The stealers also target Steam, Telegram, cryptocurrency wallets and full browser sessions.
Players should stick to the official launcher, avoid third-party client sites and be extremely wary of any link offering free access to paid mods or cheats. The convenience is never worth the compromise.
