Authored by Aayush Tyagi
What McAfee Labs found
McAfee Labs’ latest investigation into the WeedHack malware campaign found that the threat has continued to evolve even after its original command-and-control infrastructure was disrupted by McAfee. Researchers identified multiple active websites still distributing WeedHack to gamers, often by impersonating legitimate Minecraft clients, offering paid tools for free, or using trusted platforms to make malicious downloads appear credible.
Among the findings:
→ More than 6,300 attempts to access malicious sites were blocked by McAfee WebAdvisor in the past month.
→ Researchers found lookalike gaming websites designed to closely replicate legitimate projects, including their branding, feature lists, FAQs, installation guides, developer credits, and links to genuine GitHub repositories.
→ In one case, the top two Google results observed by researchers for a popular Minecraft client led to sites distributing WeedHack, demonstrating how SEO poisoning can put malicious downloads directly in gamers’ paths.
→ Nearly half of the malicious URLs identified were Discord links (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%), showing how attackers can use familiar platforms alongside fake websites to distribute malware.
→ Researchers also identified a malicious site built using an AI-powered website creation platform, illustrating how readily available tools can make it easier to launch convincing new malicious sites.
Threats like these show why protection needs to start before a malicious download ever reaches your device. McAfee helps block dangerous websites and downloads before malware has a chance to install, helping you stay focused on the game.
Threats like these show why protection needs to start before a malicious download ever reaches your device. McAfee helps block dangerous websites and downloads before malware has a chance to install, helping you stay focused on the game.
Background
2026 has seen a significant shift in malware tactics, where traditional perimeter breaching techniques are being traded in for more elusive methods, such as AI-powered phishing and widespread deployment of Info-stealer malware. Over 560,000 new malware variants are detected every day, with infostealers accounting for the most active category.
McAfee Labs has also seen a significant spike in Malware-as-a-service (MaaS) campaigns, that offer their customers access to sophisticated infostealers and backdoor malware samples at minimal cost. These campaigns provide detailed tutorials to their customers, teaching them how to target popular gaming software, develop authentic-looking websites, and implement SEO Poisoning techniques in order to bamboozle gamers and infect their systems.
Introduction
Recently, McAfee Labs has covered a Malware-as-a-service campaign, called ‘Weedhack’ that infected over 116,464 gamers and utilized SEO Poisoning techniques to infect such a large user base.
Read the original article here: Game Over: WeedHack – The Rise of Minecraft Malware-as-a-Service Campaigns
While uncovering the depths of this campaign, we’ve encountered multiple websites and file hosting services that are still active and distributing WeedHack malware. In this article, we cover some of the most prominent examples we’ve encountered in the wild to educate our readers and provide key insights on how to identify and avoid such malicious websites.
Note: This list is not exhaustive, and there may be additional websites that are not covered in this article.
Malicious websites spreading WeedHack
During our investigation of this campaign, we observed that most of these websites appear legitimate, as they are well-crafted and often mimic legitimate websites. We observed a series of dedicated brand-impersonation attacks targeting several popular Minecraft clients.
We published the original article in the first week of July, and, as a result, we’ve seen a disruption in WeedHack’s campaign: its C2 server is no longer active. Consequently, we have observed a shift in tactics by these attackers.
The WeedHack Dashboard has been taken down, yet we’ve discovered websites that are actively spreading WeedHack malware.
Out of these URLs, most belonged to file-hosting services:
- 49.6% were Discord links
- 23.4% were MediaFire links,
- 8.2% were GitHub links
- 4.6% were Dropbox links
The remaining URLs were customer-facing websites designed to deceive users.
In the last month, McAfee WebAdvisor has prevented more than 6,300 users from accessing these malicious websites. At the time of writing this blog, the following websites were still distributing WeedHack malware.

This website ‘glazed-client.com’ replicates the original website called ‘glazedclient.com’. It provides a free and open-source Minecraft add-on called ‘Glazed Client’ designed specifically for DonutSMP server.
The website contains a feature list, along with Archive, Credits, and FAQ sections, that are identical to those on the original website.

Under the download section, the website provides three download options, and all of them are infected with WeedHack.

This website has a GitHub link, which links to a legitimate GitHub repository in order to build trust with the visitors.
Example 2 – radium-client.com

The website ‘radium-client.com’ is replicating a legitimate website called ‘radiumclient.com’. The original website offers Minecraft client for $9.99 per month, but the malicious website offers the same tool for free.
The malicious replica also has a detailed feature and download section. The downloaded JAR file is infected with WeedHack.

In this instance, the malicious website contains a discord link, similar to the original website, but it points to a channel called ‘EasyClients’, that has over 1,900 members.

This channel offers 7 different DonutSMP clients for free (Image 7, Highlighted in Red) which are also infected with WeedHack.

Example 3 – seedcrackerx.github.io

In this example, we see GitHub’s web hosting service ‘GitHub.io’ being exploited by attackers. Here they are impersonating ‘SeedCrackerX’ tool, which is a Minecraft seed cracking software capable of identifying the exact world seed used to generate a Minecraft world.

Here, the malicious websites imitate the original website ‘seedcrackerx.com’, by replicating its fonts and color palette. The website also includes an elaborate tutorial and FAQ section, educating the visitors on how to properly install the tool.

Under the download section, the website offers seven versions to choose from, but all of them are infected with WeedHack. (Highlighted in Red)
This malicious website has also linked the genuine GitHub repository hosting the SeedCrackerX tool (Highlighted in Green), to appear more legitimate.
Example 4 – xenoclient.lol and xenonclient.com
Xenon Client is one of the most popular Minecraft Clients, known for being lightweight, community driven and offering niche vanilla-friendly utilities. Given its widespread popularity, this client is a prominent target for threat actors.

During our research, we identified that the top two Google search results for ‘Xenon Client’ directed users to websites (Highlighted in Red) that are spreading WeedHack.

The “xenoclient.lol” website is particularly noteworthy, for the range of features and support it offers. The website includes comprehensive download and installation guides, as well as FAQ and Credits sections. Additionally, it lists the original Xenon Client GitHub repository and features a community section for like-minded gamers, further enhancing its professional appearance.

It offers 2 purchase options for free and premium, where the premium version is listed for $5.

The free option, on the other hand, offers six download options for the main client and six additional options for the client optimizer. At the time of writing, only one download link remains operational (highlighted in red), and it delivers a payload infected with WeedHack.
Another website, “xenonclient.com,” is also targeting Minecraft players, luring them with a free version of the same client.

Similar to other websites in the campaign, this site includes an installation guide and a feature list for the Xenon Client to enhance its apparent legitimacy.

The final JAR file downloaded from this website infects users with WeedHack.
Example 5 – nova-client.com
Nova client is an open-source client designed for Minecraft Bedrock Edition.

This client is an easy target for attackers because it lacks an official website. The legitimate client is hosted on GitHub and Modrinth; however, attackers have created a spoofed website and leveraged SEO poisoning techniques to outrank the official sources in search results.

This website also includes a Features page, installation guide, and FAQ section. In addition, it displays screenshots from the legitimate Nova Client to deceive users.
What is interesting here is that attackers have also included a credits section, which is common with legitimate Minecraft client websites. However, they do not mention anyone who has actually worked on the project and instead used generic team names.

The download section provides Nova Client for Minecraft 1.21.11, but the download file spreads WeedHack malware.

Example 6 – cheatlib.xyz
CheatLib advertises that their clients have been downloaded over 1.6 million times, are free from malware and offers round-the-clock support.

Similar to other such websites, it also features a setup guide and a FAQ section to address common user issues.

They provide eight Minecraft Mods and inform users which Minecraft servers and anti-cheat systems they can bypass, as well as the current status of each mod.

Although the website offers eight distinct mods, all eight files share the same hash and distribute the WeedHack payload.

This website also links to a Discord channel called ‘CheatLib’ with over 220 users, which also provides access to WeedHack infected mods.
Example 7 – meteorclients.com

This malicious domain ‘meteorclients.com’ is impersonating a legitimate website ‘meteorclient.com’. They claim that this client has been downloaded over 10 million times and has over 15 thousand active users at any given time.

The Team section contains the names of the legitimate Meteor Client developers, which appear to have been copied from the project’s official website, to create an appearance of authenticity.

They also provide an interactive preview of Meteor client on the website, enabling users to test and familiarize themselves with the client. The website offers a single download option, which is infected with WeedHack.
Example 8 – 22qq-client.com
22qq-client is a Minecraft Mod for Crystal PVP servers.

This mod does not have a dedicated website, and attackers are exploiting this issue. This website is meant to serve as the official page for the client.

The attackers attempt to establish credibility by using screenshots from the legitimate client.

They also offer an interactive preview of the client to give users an overview of its functionality. This website provides multiple download buttons, but all of them download the same JAR file, which is infected with WeedHack.
Example 9 – kryptonclientcrack.lovable.app
Krypton Client is a paid Minecraft tool for DonutSMP server, hosted on ‘kryptonclient.org’. This malicious counterpart claims to offer a cracked version of the tool.

The attackers have used an AI-powered tool called ‘lovable.app’ that allows customers to build and launch functional web applications and websites, using natural language. Such tools make it easier for attackers to deploy new malicious domains on the fly.

The website claims that the tool has been downloaded more than five thousand times and has been thoroughly tested for safety. They offer a single download option, which is infected with WeedHack.
Example 10 – File Hosting Services
In the course of our investigation, we observed that multiple attackers were exploiting various file hosting services to spread malware.

Links to these websites are then distributed via different communication channels, such as Discord, Reddit and other online platforms.

We also observed that threat actors extended their targeting beyond Minecraft clients, compromising various popular and independent community websites within the Minecraft ecosystem.

At the time of this analysis, the following Planet Minecart links were spreading WeedHack malware.
hxxps://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar
hxxps://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jar
Similarly, we observed another community website, called EndMods was also targeted by WeedHack.

The following link is still active, at the time of publication, and is still spreading the WeedHack malware.
hxxps://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip
How To Protect Yourself Online
At McAfee Labs, we investigate threats across the digital landscape, and gamers are a frequent target. We’ve seen multiple malware-as-a-service campaigns similar to WeedHack use fake downloads, impersonated websites, malicious mods, and other lures to target gaming communities.
AI-powered tools can make it faster and easier for scammers to create convincing websites, imitate legitimate services, and launch new campaigns at scale. That makes it even more important to know what you’re downloading, and where it’s coming from.
Here are a few ways gamers can stay safer:
→ Stick to trusted sources. Download games, mods, clients, and other files from official developer websites or reputable mod platforms whenever possible. If you can’t verify the source, don’t download it.
→ Never turn off your security software for a download. Be suspicious of any mod, cheat, or client that tells you to disable your antivirus or other protections before installing it.
→ Scan files before opening them. Check downloaded mods, installers, and archives before running them — even if they came from a popular gaming community or website.
→ Be skeptical of offers that seem too good to be true. “Free” premium features, exclusive cheats, cracked software, or paid clients can be used as bait to convince gamers to download malware.
→ Check the URL before you download. Scammers can create lookalike domains and convincing copies of legitimate gaming sites. Small changes in a web address can be a sign you’re on an impersonation site.
→ Pay attention to security warnings. If your antivirus flags a download, don’t automatically assume it’s a false positive. Stop and investigate before allowing the file to run.
→ Keep your devices and software updated. Install updates for your operating system, browser, games, and security software to help protect against known vulnerabilities.
Indicator of Compromise(s)
| hxxps://glazed-client.com/ |
| hxxps://github.com/Hl3n/GambleRigMod |
| hxxps://www.radium-client.com/ |
| hxxps://discord.com/channels/1467145812906872834/ |
| hxxps://seedcrackerx.github.io/ |
| hxxps://github.com/seedcrackerx/seedcrackerx.github.io |
| hxxps://xenonclient.com/ |
| hxxps://xenoclient.lol |
| hxxps://nova-client.com/ |
| hxxps://cheatlib.xyz/ |
| hxxps://discord.com/channels/1478170973755936990 |
| hxxps://meteorclients.com |
| hxxp://22qq-client.com/ |
| hxxps://kryptonclientcrack.lovable.app |
| hxxps://github.com/lsellh/ |
| hxxps://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar |
| hxxps://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jar |
| hxxps://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip |