Cyber Security News

Top Google Results for Minecraft Client Led Gamers to Malware, McAfee Finds

Minecraft players searching for a popular client can now land on malware instead of a game tool. A renewed WeedHack campaign is using poisoned search results, copied websites and free-download lures to place dangerous Java files in front of players.

The risk is not limited to one fake page. Attackers are cloning branding, feature lists, installation guides and even links to real GitHub projects, making fraudulent Minecraft client sites look convincing at a glance.

Downloads delivered through those pages carry the WeedHack payload. McAfee analysts identified the continuing activity after the campaign’s original command-and-control infrastructure was disrupted.

The group’s dashboard is down, but its distribution network remains active, showing how quickly a malware operation can change its delivery methods.

glazed-client landing page (Source – McAfee)

The scale is notable. McAfee WebAdvisor blocked more than 6,300 attempts to reach the malicious sites in the past month, while an earlier investigation linked WeedHack to more than 116,464 infected gamers.

McAfee said in a report shared with Cyber Security News (CSN) that the campaign illustrates why a high-ranking result should not be treated as proof that a download is safe.

Top Google Results for Minecraft Client Led Gamers

Researchers found that the first two Google results for searches for Xenon Client directed users to WeedHack-spreading sites.

This is a clear example of SEO poisoning, where criminals manipulate search visibility so that a fake download page appears before, or alongside, legitimate project resources.

One of the sites, xenoclient.lol, offered free and premium options, complete with download and installation pages, FAQs, credits and a link to Xenon Client’s genuine GitHub repository.

radium-client landing page (Source – McAfee)

Another, xenonclient.com, promoted a free version of the client. Both were designed to turn a familiar search into a malware delivery route.

Other impersonation sites copied Glazed Client, Radium Client, SeedCrackerX, Nova Client, Meteor Client and 22qq-client.

In some cases, operators targeted projects without an official standalone website, exploiting the gap to outrank legitimate GitHub or mod-platform listings. A Minecraft malware loader investigation shows the broader danger of trojanized game files that appear useful to players.

The researchers also found a malicious Krypton Client page built with lovable.app, an AI-powered site-building service, underscoring how easily attackers can produce polished pages at speed.

Comparable fake download SEO campaigns have used the same trust gap outside gaming. Several pages advertised paid clients or cheats for free, while others offered many version choices that all led to infected files. The apparent choice keeps visitors inside the same malicious distribution chain.

Familiar Platforms Extend the Trap

The campaign does not rely only on lookalike domains. Of the malicious URLs McAfee identified, 49.6% were Discord links, 23.4% MediaFire links, 8.2% GitHub links and 4.6% Dropbox links.

These widely used services can make a malicious file seem less suspicious when it is shared in community chats or repositories. Researchers also observed tainted downloads hosted through community sites, including Planet Minecraft and EndMods.

Links can then be promoted through Discord, Reddit and other online spaces, widening the audience beyond users who arrive through a search engine. The approach echoes YouTube and search poisoning abuse that previously drove Minecraft players toward WeedHack.

The safest response is to start with the project’s verified developer page or a reputable mod platform, rather than choosing the first search result.

Google search results for ‘Xenon Client’ (Source – McAfee)

Players should compare the full URL carefully, avoid cracked or supposedly free premium clients, and treat a request to disable security software as a serious warning sign.

Downloaded JAR files, mods, installers and archives should be scanned before they are opened, even when they came from a popular-looking community.

If a security tool flags a file, stop and investigate instead of assuming the alert is wrong. Keeping the operating system, browser, games and security tools updated also reduces exposure to known weaknesses.

For families and server communities, the practical lesson is simple: share verified download locations and report lookalike pages quickly.

fake Minecraft mods threat demonstrates why a promised gameplay advantage can have consequences far beyond a single compromised account.

Indicators of compromise (IoCs):-

TypeIndicatorDescription
Malicious URLhxxps://glazed-client.com/Lookalike Glazed Client website distributing WeedHack
Malicious repositoryhxxps://github.com/Hl3n/GambleRigModGitHub repository associated with WeedHack distribution
Malicious URLhxxps://www.radium-client.com/Fake Radium Client download website
Discord channelhxxps://discord.com/channels/1467145812906872834/EasyClients Discord channel linked to infected clients
Malicious URLhxxps://seedcrackerx.github.io/Fake SeedCrackerX website hosting infected downloads
Malicious repositoryhxxps://github.com/seedcrackerx/seedcrackerx.github.ioGitHub repository associated with fake SeedCrackerX site
Malicious URLhxxps://xenonclient.com/Fake Xenon Client website distributing WeedHack
Malicious URLhxxps://xenoclient.lolXenon Client impersonation website distributing WeedHack
Malicious URLhxxps://nova-client.com/Fake Nova Client download website
Malicious URLhxxps://cheatlib.xyz/Website offering WeedHack-infected Minecraft mods
Discord channelhxxps://discord.com/channels/1478170973755936990CheatLib Discord channel associated with infected mods
Malicious domainhxxps://meteorclients.comFake Meteor Client download website
Malicious URLhxxp://22qq-client.com/Fake 22qq-client website distributing an infected JAR file
Malicious URLhxxps://kryptonclientcrack.lovable.appFake cracked Krypton Client website
Malicious repositoryhxxps://github.com/lsellh/GitHub repository associated with WeedHack distribution
Malicious file URLhxxps://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jarWeedHack-infected Minecraft mod download
Malicious file URLhxxps://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jarWeedHack-infected Minecraft mod download
Malicious file URLhxxps://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zipActive WeedHack-distributing ZIP archive

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

2 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

8 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

19 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

16 hours ago