discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content

McAfee Labs says Minecraft players are being targeted by Weedhack malware spread through YouTube and SEO poisoning, while CountLoader and pirated-content miner campaigns are also active.

By Ravie Lakshmanan·Jun 3·thehackernews.com·3 min read

Intelligence analysis by GPT-5.4 Mini

Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
Image: thehackernews.com

McAfee Labs links three active malware campaigns to different lure chains: fake Minecraft mods on YouTube, a large CountLoader outbreak, and crypto miners hidden behind pirated streaming sites. The common theme is low-friction infection paths that reach ordinary users, then quietly steal data or money.

Why it matters

This is a broad consumer-security story with real-world impact: it targets Minecraft players, cracked-software users, and people seeking pirated streams. It also shows how malware operators are combining social platforms, search poisoning, USB spread, and crypto theft to scale infections.

Hackers are hiding bad software inside fake Minecraft mods, cracked apps, and pirated video sites. It is like handing someone a toy with a trap inside, and once it is opened, the attacker can sneak into the computer, steal things, or make it mine digital money.

Analysis

Weedhack targets Minecraft players

McAfee Labs says a Minecraft-focused malware-as-a-service campaign called Weedhack has been active since January 2026. The attackers impersonate Minecraft clients and mods, push traffic through SEO poisoning and YouTube videos, and use malicious JAR files to infect victims. The researchers identified 3,820 unique malicious JARs and more than 240 URLs tied to distribution.

The infrastructure is unusually polished for a criminal toolset. McAfee says the operation includes an enterprise-style dashboard at weedhack[.]to where customers can view stolen credentials and system details, monitor compromised machines, and generate custom payloads for Minecraft versions 1.21.0 through 1.21.11. The malware chain uses a file called DonutDupe.jar, then relies on EtherHiding to fetch the next-stage C2 details from the Ethereum blockchain. Later stages collect system information, adjust Microsoft Defender exclusions, establish persistence, and ultimately enable remote access.

A low-cost malware market

The group advertises through a Telegram channel with more than 850 members. McAfee says the tool is offered in a free tier with infostealer features and in a premium tier starting at $4.99 per month, or $24.99 for a lifetime license. The premium version adds webcam access, keylogging, reverse shell access, screen sharing, and file transfer. The company also says the malware has been used for cyberbullying, with some users reportedly recording victims on webcams and posting the clips as trophies.

CountLoader and pirated-content miners

The same report says CountLoader has compromised an estimated 86,000 unique machines. It is typically spread through cracked software sites, starts with an EXE that launches PowerShell, and then uses mshta.exe to run an obfuscated JavaScript loader. The loader can deploy multiple payloads, including Cobalt Strike, PureHVNC RAT, and a crypto clipper that rewrites clipboard content to hijack cryptocurrency transfers. About 9,000 infections were associated with USB and removable-media spread, and McAfee says it sinkholed part of the infrastructure by registering a fake C2 domain.

McAfee also describes a long-running campaign using illegal movie and TV streaming sites to deliver a cryptocurrency miner disguised as a fake video-player update. That payload uses DLL side-loading to install a fork of SilentCryptoMiner. The biggest infection clusters were seen in the U.S., Germany, and India, showing how widely these campaigns are reaching.

Key points

  • Weedhack is a Minecraft-themed malware-as-a-service campaign active since January 2026.
  • McAfee found 3,820 malicious JAR files and more than 240 related URLs.
  • CountLoader has reportedly infected about 86,000 machines and can spread through USB drives.
  • Pirated streaming sites are also being used to deliver a crypto miner disguised as an update.
  • The heaviest Weedhack infections were seen in the U.S., Germany, and India.
The Upside

McAfee says it has already identified the infrastructure, traced the delivery methods, and even sinkholed part of the CountLoader network. That gives defenders concrete indicators to block, hunt, and remove the malware before more users are fooled.

The Downside

The campaigns are built for scale: they use search results, YouTube, cracked software, USB spread, and fake updates to reach people where they already are. Because Weedhack offers free access and tutorials, the barrier to entry is low, which could keep abuse and harassment growing.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritycryptomalwareunited-statesgermanyindia

Author

Ravie Lakshmanan

Intelligence analysis by

GPT-5.4 Mini

Published

Jun 3, 2026

Source

thehackernews.com

Share

Topics

securitycryptomalwareunited-statesgermanyindia

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…