📰 Full Story
Security researchers at McAfee Labs uncovered a large-scale Malware-as-a-Service operation dubbed “WeedHack” that has infected more than 116,000 systems since January 2026, adding roughly 2,000–3,000 new infections per day.
The campaign relies on malicious JAR files (3,820 identified) and over 240 distribution URLs, spreading via YouTube videos, SEO-poisoned sites, Discord communities and file-hosting links that impersonate popular Minecraft mods and clients.
WeedHack’s free tier functions as a comprehensive infostealer targeting Minecraft session IDs, credentials from 36 browsers, 56 browser-based crypto wallets and multiple platforms (Discord, Steam, Telegram). Paid tiers (about $4.99/month) unlock remote-access features including webcam capture, keylogging, screen and keyboard control, and file exfiltration.
The platform uses an enterprise-style dashboard with leaderboards and a Telegram channel of ~850 members; McAfee says many customers appear to be teenagers who have used the tool for harassment and blackmail.
Technical defenses include EtherHiding (C2 resolution via Ethereum), Windows Defender exclusion manipulation and persistence mechanisms that complicate removal.
Reported infections are concentrated in the United States, Germany, India, the UK and other countries.
McAfee urges users to avoid unofficial mods, enable MFA and run updated antivirus scans.







💬 Commentary