Minecraft players searching for a popular client can now land on malware instead of a game tool. A renewed WeedHack campaign is using poisoned search results, copied websites and free-download lures to place dangerous Java files in front of players.
The risk is not limited to one fake page. Attackers are cloning branding, feature lists, installation guides and even links to real GitHub projects, making fraudulent Minecraft client sites look convincing at a glance.
Downloads delivered through those pages carry the WeedHack payload. McAfee analysts identified the continuing activity after the campaign’s original command-and-control infrastructure was disrupted.
The group’s dashboard is down, but its distribution network remains active, showing how quickly a malware operation can change its delivery methods.
The scale is notable. McAfee WebAdvisor blocked more than 6,300 attempts to reach the malicious sites in the past month, while an earlier investigation linked WeedHack to more than 116,464 infected gamers.
McAfee said in a report shared with Cyber Security News (CSN) that the campaign illustrates why a high-ranking result should not be treated as proof that a download is safe.
Researchers found that the first two Google results for searches for Xenon Client directed users to WeedHack-spreading sites.
This is a clear example of SEO poisoning, where criminals manipulate search visibility so that a fake download page appears before, or alongside, legitimate project resources.
One of the sites, xenoclient.lol, offered free and premium options, complete with download and installation pages, FAQs, credits and a link to Xenon Client’s genuine GitHub repository.
Another, xenonclient.com, promoted a free version of the client. Both were designed to turn a familiar search into a malware delivery route.
Other impersonation sites copied Glazed Client, Radium Client, SeedCrackerX, Nova Client, Meteor Client and 22qq-client.
In some cases, operators targeted projects without an official standalone website, exploiting the gap to outrank legitimate GitHub or mod-platform listings. A Minecraft malware loader investigation shows the broader danger of trojanized game files that appear useful to players.
The researchers also found a malicious Krypton Client page built with lovable.app, an AI-powered site-building service, underscoring how easily attackers can produce polished pages at speed.
Comparable fake download SEO campaigns have used the same trust gap outside gaming. Several pages advertised paid clients or cheats for free, while others offered many version choices that all led to infected files. The apparent choice keeps visitors inside the same malicious distribution chain.
The campaign does not rely only on lookalike domains. Of the malicious URLs McAfee identified, 49.6% were Discord links, 23.4% MediaFire links, 8.2% GitHub links and 4.6% Dropbox links.
These widely used services can make a malicious file seem less suspicious when it is shared in community chats or repositories. Researchers also observed tainted downloads hosted through community sites, including Planet Minecraft and EndMods.
Links can then be promoted through Discord, Reddit and other online spaces, widening the audience beyond users who arrive through a search engine. The approach echoes YouTube and search poisoning abuse that previously drove Minecraft players toward WeedHack.
The safest response is to start with the project’s verified developer page or a reputable mod platform, rather than choosing the first search result.
Players should compare the full URL carefully, avoid cracked or supposedly free premium clients, and treat a request to disable security software as a serious warning sign.
Downloaded JAR files, mods, installers and archives should be scanned before they are opened, even when they came from a popular-looking community.
If a security tool flags a file, stop and investigate instead of assuming the alert is wrong. Keeping the operating system, browser, games and security tools updated also reduces exposure to known weaknesses.
For families and server communities, the practical lesson is simple: share verified download locations and report lookalike pages quickly.
A fake Minecraft mods threat demonstrates why a promised gameplay advantage can have consequences far beyond a single compromised account.
Indicators of compromise (IoCs):-
| Type | Indicator | Description |
|---|---|---|
| Malicious URL | hxxps://glazed-client.com/ | Lookalike Glazed Client website distributing WeedHack |
| Malicious repository | hxxps://github.com/Hl3n/GambleRigMod | GitHub repository associated with WeedHack distribution |
| Malicious URL | hxxps://www.radium-client.com/ | Fake Radium Client download website |
| Discord channel | hxxps://discord.com/channels/1467145812906872834/ | EasyClients Discord channel linked to infected clients |
| Malicious URL | hxxps://seedcrackerx.github.io/ | Fake SeedCrackerX website hosting infected downloads |
| Malicious repository | hxxps://github.com/seedcrackerx/seedcrackerx.github.io | GitHub repository associated with fake SeedCrackerX site |
| Malicious URL | hxxps://xenonclient.com/ | Fake Xenon Client website distributing WeedHack |
| Malicious URL | hxxps://xenoclient.lol | Xenon Client impersonation website distributing WeedHack |
| Malicious URL | hxxps://nova-client.com/ | Fake Nova Client download website |
| Malicious URL | hxxps://cheatlib.xyz/ | Website offering WeedHack-infected Minecraft mods |
| Discord channel | hxxps://discord.com/channels/1478170973755936990 | CheatLib Discord channel associated with infected mods |
| Malicious domain | hxxps://meteorclients.com | Fake Meteor Client download website |
| Malicious URL | hxxp://22qq-client.com/ | Fake 22qq-client website distributing an infected JAR file |
| Malicious URL | hxxps://kryptonclientcrack.lovable.app | Fake cracked Krypton Client website |
| Malicious repository | hxxps://github.com/lsellh/ | GitHub repository associated with WeedHack distribution |
| Malicious file URL | hxxps://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar | WeedHack-infected Minecraft mod download |
| Malicious file URL | hxxps://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jar | WeedHack-infected Minecraft mod download |
| Malicious file URL | hxxps://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip | Active WeedHack-distributing ZIP archive |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…