Fake Minecraft Downloads Are Pushing 'Weedhack' Malware to Gamers
Researchers at McAfee blocked more than 6,300 attempts to reach lookalike gaming sites that hand out malware instead of a cheat client.

Key points
- McAfee Labs said it blocked more than 6,300 attempts to reach malicious sites pushing a malware family called Weedhack.
- The sites impersonate legitimate Minecraft cheat clients, copying their branding, feature lists and FAQ pages.
- Victims are gamers searching for free client downloads, who end up installing malware that runs quietly on their PC.
- The campaign is still live, meaning fresh lookalike domains keep appearing in search results.
- Anyone who downloaded a Minecraft client from an unfamiliar site recently should treat that machine as suspect.
Gamers hunting for free Minecraft add-ons are walking into a malware trap that has been running for months. Security researchers at McAfee say a family of malicious software called Weedhack is being handed out through websites that pretend to be legitimate Minecraft "clients", the tweaked versions of the game players use to add cheats, mods or performance tweaks.
The scale is not small. McAfee Labs said it detected and blocked more than 6,300 attempts by its own customers to reach the fake sites, according to reporting from The Hacker News. That is only the traffic McAfee can see. The real number of people who tried to download something is almost certainly higher.
How does the scam actually work?
The criminals build fake websites that look like real Minecraft cheat projects, then wait for players to find them through search engines. The pages copy the branding, feature lists and even the frequently-asked-questions section of the genuine tools they impersonate. To a teenager looking for a free download, the site looks entirely normal.
Instead of a game client, the download drops Weedhack: malicious software that installs quietly and gives the attackers a foothold on the victim's computer. From there, the usual playbook applies. That means stealing saved passwords, grabbing session tokens for accounts like Discord, and in some cases installing further payloads later.
Why is Minecraft such a good lure?
Minecraft has a huge, young player base that is very used to downloading unofficial software. Cheat clients, mod loaders and "free premium" tools are a normal part of the culture. That makes it easy for criminals to blend in.
Search-engine optimisation, the practice of tuning a website so it ranks near the top of Google results, is doing the heavy lifting here. The failure mode here is depressingly familiar: a kid searches "free Minecraft client download", clicks the first result that is not marked as an ad, and hands their PC over. No phishing email required.
| Detail | What McAfee found |
|---|---|
| Malware family | Weedhack |
| Blocked access attempts | More than 6,300 |
| Delivery method | Fake Minecraft client websites |
| Disguise tactics | Copied branding, feature lists, FAQs |
What should players and parents actually do?
If someone in your house downloaded a Minecraft client from a site you do not recognise in the past few weeks, treat that computer as compromised until proven otherwise. Run a full antivirus scan. Change the passwords for any accounts used on that machine, especially Minecraft, Microsoft, Discord and email, and do it from a different device.
Stick to official sources. The Minecraft launcher itself comes from Microsoft. Popular mod loaders like Fabric and Forge have official project sites, and reputable modpacks live on well-known platforms such as CurseForge or Modrinth. If a "free" client promises paid features unlocked, that is the pitch, and the payload.
In practice this campaign will keep working as long as search engines keep ranking freshly registered lookalike domains. One thing the post-mortem will say, again, is that endpoint detection catches the tail end of a problem that started with a Google search.
Operational takeaway: if your users can download and run unsigned executables from any website they like, your malware problem is a policy problem, not a product one.



