Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
McAfee Labs says Minecraft players are being targeted by Weedhack malware spread through YouTube and SEO poisoning, while CountLoader and pirated-content miner campaigns are also active.
Intelligence analysis by GPT-5.4 Mini

McAfee Labs links three active malware campaigns to different lure chains: fake Minecraft mods on YouTube, a large CountLoader outbreak, and crypto miners hidden behind pirated streaming sites. The common theme is low-friction infection paths that reach ordinary users, then quietly steal data or money.
Hackers are hiding bad software inside fake Minecraft mods, cracked apps, and pirated video sites. It is like handing someone a toy with a trap inside, and once it is opened, the attacker can sneak into the computer, steal things, or make it mine digital money.
Analysis
Weedhack targets Minecraft players
McAfee Labs says a Minecraft-focused malware-as-a-service campaign called Weedhack has been active since January 2026. The attackers impersonate Minecraft clients and mods, push traffic through SEO poisoning and YouTube videos, and use malicious JAR files to infect victims. The researchers identified 3,820 unique malicious JARs and more than 240 URLs tied to distribution.
The infrastructure is unusually polished for a criminal toolset. McAfee says the operation includes an enterprise-style dashboard at weedhack[.]to where customers can view stolen credentials and system details, monitor compromised machines, and generate custom payloads for Minecraft versions 1.21.0 through 1.21.11. The malware chain uses a file called DonutDupe.jar, then relies on EtherHiding to fetch the next-stage C2 details from the Ethereum blockchain. Later stages collect system information, adjust Microsoft Defender exclusions, establish persistence, and ultimately enable remote access.
A low-cost malware market
The group advertises through a Telegram channel with more than 850 members. McAfee says the tool is offered in a free tier with infostealer features and in a premium tier starting at $4.99 per month, or $24.99 for a lifetime license. The premium version adds webcam access, keylogging, reverse shell access, screen sharing, and file transfer. The company also says the malware has been used for cyberbullying, with some users reportedly recording victims on webcams and posting the clips as trophies.
CountLoader and pirated-content miners
The same report says CountLoader has compromised an estimated 86,000 unique machines. It is typically spread through cracked software sites, starts with an EXE that launches PowerShell, and then uses mshta.exe to run an obfuscated JavaScript loader. The loader can deploy multiple payloads, including Cobalt Strike, PureHVNC RAT, and a crypto clipper that rewrites clipboard content to hijack cryptocurrency transfers. About 9,000 infections were associated with USB and removable-media spread, and McAfee says it sinkholed part of the infrastructure by registering a fake C2 domain.
McAfee also describes a long-running campaign using illegal movie and TV streaming sites to deliver a cryptocurrency miner disguised as a fake video-player update. That payload uses DLL side-loading to install a fork of SilentCryptoMiner. The biggest infection clusters were seen in the U.S., Germany, and India, showing how widely these campaigns are reaching.
Key points
- Weedhack is a Minecraft-themed malware-as-a-service campaign active since January 2026.
- McAfee found 3,820 malicious JAR files and more than 240 related URLs.
- CountLoader has reportedly infected about 86,000 machines and can spread through USB drives.
- Pirated streaming sites are also being used to deliver a crypto miner disguised as an update.
- The heaviest Weedhack infections were seen in the U.S., Germany, and India.
McAfee says it has already identified the infrastructure, traced the delivery methods, and even sinkholed part of the CountLoader network. That gives defenders concrete indicators to block, hunt, and remove the malware before more users are fooled.
The campaigns are built for scale: they use search results, YouTube, cracked software, USB spread, and fake updates to reach people where they already are. Because Weedhack offers free access and tutorials, the barrier to entry is low, which could keep abuse and harassment growing.



