WeedHack MaaS Infostealer — Trojanized Minecraft Mods/Clients via YouTube + SEO Poisoning, 36-Browser & Crypto-Wallet Credential Theft with Paid RAT Tier (CVE-N/A) — Threadlinqs Intelligence
As of 2026-06-02, WeedHack MaaS Infostealer — Trojanized Minecraft Mods/Clients via YouTube + SEO Poisoning, 36-Browser & Crypto-Wallet Credential Theft with Paid RAT Tier (CVE-N/A) is a high-severity malware threat attributed to WeedHack Operators, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 33 indicators of compromise.
Threat ID: TL-2026-0665 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: WeedHack Operators · FINANCIAL
WeedHack is a clear-net malware-as-a-service (MaaS) infostealer targeting Minecraft players, distributed as trojanized Fabric mods/clients/cheats promoted via YouTube and SEO poisoning. McAfee Labs
WeedHack is a malware-as-a-service infostealer-plus-RAT platform aimed squarely at the Minecraft modding community. Unlike most infostealers it is hosted on the clear net with an open free tier, lowering the barrier to entry for unskilled operators. Customers receive a web dashboard (seller panel at weedhack.cy) with a victim overview, per-system profiles keyed by buyer UUID, stolen-data browsing, and a payload builder that produces trojanized JARs for Minecraft Java versions 1.21.0 through 1.21.10. McAfee Labs researcher Aayush Tyagi attributes 116,464 infections since January 2026, averaging 2,000-3,000 per day, delivered through 3,820+ unique malicious JAR files across 240+ distribution URLs. Victims concentrate in the United States, Germany, India, the United Kingdom, and Italy.
Distribution relies on social engineering rather than exploitation. Operators publish YouTube videos (some voice-narrated, 7,500+ views) demonstrating popular Minecraft clients with download links in descriptions and comments, and poison search results for legitimate open-source client names including Meteor, Radium, Wurst, Aristois, LiquidBounce, Impact, Future, Inertia, Cornos, WWE, 3arthh4ck, Salhack, Phobos and Gamesense. Fake distribution sites impersonate real projects (e.g. Skytils) and even link the genuine GitHub repository and Discord server to manufacture legitimacy — effective because many targeted clients only maintain GitHub pages, not official websites.
The payload is a multi-stage Java/Fabric mod chain. Stage 1 is a loader (mod.jar ~500KB in v1; the hardened NewMod.jar ~1.5MB in v2 adds JNIC native obfuscation and an Ethereum JSON-RPC blockchain C2 fallback) whose onInitialize() entry point in me/mclauncher/LoaderClient extracts the Minecraft session token immediately via MinecraftClient.getInstance().getSession(). Stage 1 pulls Stage 2 (module.jar ~2MB), the information stealer, which harvests cookies and DPAPI-decrypted passwords from 36+ Chromium/Gecko browsers (Chrome, Edge, Brave, Opera/OperaGX, Vivaldi, Yandex, Chromium, Thorium, 7Star, CentBrowser, Chedot, Kometa and more), 56 browser-extension crypto wallets (MetaMask, Phantom, Coinbase, Trust Wallet, Exodus Web3, Ronin, Keplr, Solflare, etc.), 12 desktop wallets (Exodus, Atomic, Electrum, Zcash, Armory, Bytecoin, Jaxx, Guarda, Coinomi, Ethereum), Discord tokens (encrypted/legacy/browser), Telegram tdata, and five Minecraft launchers (Lunar accounts.json, Essential microsoft_accounts.json, Feather account.txt, Modrinth app.db, vanilla servers.dat). It also captures screenshots and recursively searches for files matching keywords such as password, seed, wallet, crypto, 2fa and backup.
Premium buyers receive Stage 3 (Component.jar), a Java RAT providing a jnativehook-based real-time keylogger over Socket.IO, 25 FPS webcam capture and WebP screen share over WebSocket, a Runtime.exec()/ProcessBuilder remote shell, java.awt.Robot keyboard/mouse input injection, and a directory/file browser supporting upload and download. Persistence is handled by SecurityManager.jar, which installs into %APPDATA%\Microsoft\SecurityUpdates\, drops Updater.vbs, registers a HIGHEST-runlevel ONLOGON scheduled task named JavaSecurityUpdater, writes an HKCU Run key, adds a Windows Defender exclusion for C:\Users via hidden PowerShell (Add-MpPreference, Defender Event ID 5007), and obtains elevation through an ElevationHelper runas/CMSTPLUA UAC bypass. A February 2026 update added a secondary PureHVNC/PureLogs backdoor (Pjibf.exe, .NET Reactor packed) executed after UAC elevation via elevator.jar, beaconing to 45.141.119.34:50169 and WebSocket remotev2.whreceive.ru/ws/client. McAfee notes the operator community runs through a Telegram channel of 800+ members, and that many buyers appear to be teenagers and young adults who use the RAT tier to harass and cyberbully victims.
Weaknesses (CWE)
CWE-506, CWE-829, CWE-507
Target sectors: gaming, consumer, cryptocurrency, individuals
Target regions: North America, Europe, Asia
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 33 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1587.001, T1583.001, T1608.006, T1585, T1189, T1204.002, T1059.001, T1059.005, T1059.003, T1053.005