Weedhack Malware-as-a-Service Steals Minecraft Credentials, Hijacks Accounts
Key Takeaways Weedhack is a sophisticated Malware-as-a-Service (MaaS) platform targeting Minecraft players since at least January 2026. It spreads through malicious Minecraft mods and clients,...
Key Takeaways
- Weedhack is a sophisticated Malware-as-a-Service (MaaS) platform targeting Minecraft players since at least January 2026.
- It spreads through malicious Minecraft mods and clients, distributed via YouTube, search engine manipulation, and fake websites.
- The malware steals credentials, cryptocurrency, and enables remote control, webcam access, and keylogging, with subscriptions starting at $5/month.
- Weedhack leverages Ethereum blockchain for command-and-control, making it highly resilient to traditional takedown attempts.
- Beyond financial theft, the platform is actively used for cyberbullying and harassment within gaming communities.
The gaming community is confronting a novel and concerning cyber threat with the emergence of Weedhack, a Malware-as-a-Service (MaaS) operation. This sophisticated platform, active since at least January 2026, transforms popular games like Minecraft into vectors for credential theft, cryptocurrency draining, and account hijacking, according to researchers.
Table Of Content
Weedhack’s distribution relies on deceptive tactics, including YouTube videos, search engine optimization poisoning, and meticulously crafted fake Minecraft mod websites. These sites are designed to appear legitimate, luring unsuspecting players who are searching for game modifications into downloading infected files. The subsequent compromise can lead to significant data loss and complete account takeover.
The operators behind Weedhack claim to have achieved over 116,000 “hits,” with access to the MaaS platform available for as little as $5 per month.
The Weedhack MaaS Ecosystem
Researchers at PolySwarm have characterized Weedhack as a fully developed MaaS platform, complete with a business structure akin to legitimate software services. This platform includes various subscription tiers, comprehensive operational tutorials, a dedicated malware builder, customer support, and victim management dashboards. Such a robust infrastructure lowers the barrier to entry for cybercriminals, even those with minimal technical expertise.
The affordability and detailed documentation provided by Weedhack have made it particularly appealing to younger individuals, including teenagers and young adults. PolySwarm’s analysis indicates that many of the observed users were primarily interested in illicitly acquiring Minecraft accounts or gaining unauthorized access to other players’ systems. As a report by Polyswarm shared with Cyber Security News (CSN) highlights, this combination of easy access and a vulnerable demographic within gaming communities fosters a dangerous environment for abuse.
A distinguishing feature of Weedhack, beyond its competitive pricing, is its technical sophistication. The operation utilizes Ethereum blockchain infrastructure to deliver command-and-control (C2) instructions. This decentralized approach significantly complicates efforts by cybersecurity defenders to disrupt the operation and track its architects, making it more resilient to traditional takedown methods.
Infection Chain and Capabilities
Victims typically become infected after downloading trojanized Minecraft mods or clients, which are distributed as Java Archive (JAR) files. Upon execution, the malware stealthily relaunches itself via javaw.exe to conceal console activity. It then proceeds to decrypt embedded Ethereum endpoints and RSA public keys, retrieving crucial infrastructure details from smart contracts on the blockchain.
In a subsequent phase, Weedhack employs JNIC obfuscation, converting Java bytecode into native code. This technique significantly hinders analysis by security researchers. The malware then performs system reconnaissance, disables Windows Defender, captures screenshots, and begins to harvest sensitive data including browser credentials, cookies, and Discord tokens. Additional malicious payloads are downloaded, persistence mechanisms are established, and all collected data is exfiltrated to attacker-controlled servers.
Even the free tier of Weedhack offers alarming capabilities, enabling attackers to steal passwords and cookies from 36 different browsers, compromising 56 browser-based and 12 desktop cryptocurrency wallets, and pilfering credentials from popular platforms such as Discord, Steam, and Telegram. Premium subscriptions extend these capabilities further, granting access to a victim’s webcam, keylogging functionality, reverse shell execution, remote desktop control, and screen-sharing, effectively transforming the compromised device into a comprehensive surveillance tool.
Researchers have identified over 3,820 malicious JAR files and more than 240 distribution URLs linked to the Weedhack ecosystem. The campaign specifically targets users seeking well-known Minecraft clients, including Meteor Client, Radium Client, Wurst Client, and LiquidBounce, among others.
Beyond Financial Gain: Cyberbullying and Abuse
The threats posed by Weedhack extend beyond financial exploitation. Investigations have uncovered unsettling evidence that the platform is actively being used for harassment and cyberbullying. Reports indicate that customers have leveraged the remote-access features to monitor victims via their webcams, engage in intimidation tactics, and in some instances, disseminate compromising images and videos within online criminal networks.
This reveals a distressing dimension of harm that surpasses mere data theft or drained financial accounts. When attackers and victims are part of the same gaming community, the psychological repercussions of surveillance and intimidation can be profound. Weedhack effectively transforms a shared social space into a hunting ground for malicious actors.
What You Should Do
- Verify Sources: Treat any downloaded Minecraft mod or Java-based client as potentially malicious unless it originates from an absolutely trusted and verified source.
- Enable Multi-Factor Authentication (MFA): Implement MFA on all gaming accounts, email, social media, and cryptocurrency wallets to add an extra layer of security.
- Maintain Updated Security Software: Ensure your operating system, web browsers, and antivirus software are always up to date.
- Exercise Caution with Links and Downloads: Be extremely wary of suspicious links in YouTube comments, forum posts, or unofficial websites claiming to offer game mods.
- Educate Young Users: Parents and guardians should educate younger players about the risks of downloading unofficial game content and sharing personal information online.
- Employ Dynamic Analysis: Security teams should move beyond static signature-based detection and utilize dynamic behavioral analysis and infrastructure correlation to identify and mitigate threats like Weedhack, which leverage blockchain for C2.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.