HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

WeedHack Malware Campaign Infects Over 116,000 Minecraft Systems, Harvesting Credentials and Crypto Wallets

WeedHack, a malware‑as‑a‑service platform, has infected more than 116 000 Minecraft clients by distributing malicious mods through YouTube and SEO‑poisoned search results. The infostealer exfiltrates session IDs, browser cookies, crypto wallet files, and messaging credentials, posing a significant third‑party risk for organizations whose staff use gaming tools on corporate devices.

LiveThreat™ Intelligence · 📅 June 03, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
4 recommended
📰
Source
bleepingcomputer.com

WeedHack Malware Campaign Infects Over 116,000 Minecraft Systems, Harvesting Credentials and Crypto Wallets

What Happened – A malware‑as‑a‑service operation named WeedHack has compromised more than 116 000 Minecraft clients since January 2026. The infostealer is delivered via malicious mods, cheats and utilities promoted on YouTube and through SEO‑poisoned search results. Victims’ session IDs, browser cookies, cryptocurrency wallet files, Discord, Steam and Telegram credentials, plus screenshots, are exfiltrated to a public dashboard.

Why It Matters for TPRM

  • Third‑party mod distributors and hosting platforms become inadvertent infection vectors.
  • Stolen credentials can be leveraged against corporate VPNs, SSO providers, and crypto‑related services used by employees.
  • The free‑tier dashboard provides attackers with real‑time victim intelligence, increasing the speed of downstream attacks on supply‑chain partners.

Who Is Affected – Gaming and entertainment firms, SaaS providers hosting mod repositories, cloud‑hosting services, advertising networks that monetize gaming content, and any organization whose employees use Minecraft‑related tools on corporate devices.

Recommended Actions

  • Audit all employee endpoints for unauthorized Minecraft clients or mods.
  • Block download of executable JAR files from unverified URLs and enforce application allow‑lists.
  • Require MFA for accounts that could be compromised via stolen session IDs or passwords.
  • Conduct threat‑intel monitoring for new WeedHack distribution URLs and related YouTube channels.

Technical Notes – Distribution via YouTube video descriptions/comments and SEO‑poisoned sites; payload is a Java‑based JAR file that runs as a stealthy infostealer. Data stolen includes session IDs, cookies, 36 browsers, 56 crypto add‑ons, 12 desktop wallets, Discord/Steam/Telegram credentials, screenshots, and remote‑control capabilities in the premium tier. Source: BleepingComputer

📰 Original Source
https://www.bleepingcomputer.com/news/security/over-116-000-minecraft-systems-infected-in-weedhack-malware-campaign/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

Data exposure is where consent and DSAR readiness get tested.

When personal data leaks, regulators ask what consent you held and how fast you can answer a subject request. The Verisq AI Trust Operations platform, with CookiePLUS, keeps that posture audit-ready under GDPR and CCPA.

Explore the Verisq AI Trust Operations platform →