Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

WeedHack Minecraft Malware‑as‑Service Persists via Fake Client Sites After C2 Takedown

McAfee Labs reports that ten fake Minecraft client sites are still distributing the WeedHack infostealer after its command‑and‑control server was disrupted. The campaign uses SEO poisoning and brand impersonation to steal credentials and crypto wallets, underscoring the need for robust SOC 2 access controls and security‑awareness training.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 securityaffairs.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
✅
Actions
3 recommended
📰
Source
securityaffairs.com

WeedHack Minecraft Malware‑as‑a‑Service Persists via Fake Client Sites After C2 Takedown

What Happened — McAfee Labs identified ten active fake Minecraft client sites still distributing the WeedHack infostealer, even after the campaign’s command‑and‑control (C2) server was taken down. The malicious sites use SEO poisoning to rank at the top of Google results and continue to harvest session cookies, passwords, browser data, and cryptocurrency wallets.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates how attackers can bypass technical controls by exploiting user‑facing web content; SOC 2 Access Control (CC6.1) and Security Awareness Training are essential to mitigate such social‑engineering vectors.
  • Ongoing distribution after a C2 takedown highlights the need for continuous monitoring of third‑party content and evidence collection to prove due diligence during audits.

Who Is Affected — Gaming‑related SaaS providers, Minecraft client developers, and end‑users who download client software from the web.

Recommended Actions

  • Review and tighten web‑content vetting processes; enforce strict URL verification and code‑signing for downloadable clients.
  • Update security awareness programs to include phishing via SEO‑poisoned sites and fake software downloads.
  • Implement continuous monitoring of brand‑related search results and external domains for malicious impersonation.

Source: Security Affairs

Technical Notes — The campaign leverages SEO poisoning, fake client websites, and an Ethereum‑based “EtherHiding” technique to retrieve C2 addresses. Malware functions as an infostealer, exfiltrating credentials, cookies, and crypto wallet data. Source: [Security Affairs]

📰 Original Source
https://securityaffairs.com/197784/malware/fake-minecraft-sites-are-still-spreading-weedhack-after-c2-takedown.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →