Cyber Dive

WeedHack is a free Minecraft malware platform infecting 2,000 computers a day. Teenagers are using it to spy on and extort their classmates.

Published Monday, June 08, 2026

TL;DR

You have probably taught your child not to talk to strangers online. WeedHack is a different problem. It is a Minecraft malware platform that costs nothing to use and has infected 116,000 computers since January 2026, and the people buying it are teenagers using it against kids they already know.

​Stolen webcam footage. Leaked private messages. Extortion campaigns running through Telegram. Here is how the trap works and how to make sure your child is not in it.

When most parents think about digital threats to their children, they picture adult predators, corporate data breaches, or anonymous criminals operating from the other side of the world.

They think about strangers.

What they do not picture is the kid sitting two rows behind their child in third period.

At Cyber Dive, tracking emerging threats to children online is part of what we do. WeedHack is not a distant or theoretical risk. It is active, it is growing, and it is operating in the same gaming communities your child is already part of.

A cybersecurity investigation published by McAfee Labs in June 2026 uncovered a malware operation called WeedHack that has been quietly spreading through the Minecraft community since the beginning of the year.

By the time researchers blew the operation open, it had infected more than 116,000 computers. It was adding between 2,000 and 3,000 new victims every single day. And it was being used not by sophisticated criminal organizations, but by teenagers, to spy on, steal from, and extort their own classmates.

This is not a story about a distant threat. It is a story about what is already happening in schools, Discord servers, and Telegram channels right now. And it starts with a free download and a Minecraft mod.

Screenshot of the WeedHack malware-as-a-service operator dashboard discovered by McAfee Labs researchers, showing victim counts, stolen credential summaries, and infected system profiles.

WeedHack’s operator dashboard, uncovered by McAfee Labs. A polished, professional interface for running a cybercrime operation, available to anyone with a Discord account. Source: McAfee

Screenshot of the WeedHack malware-as-a-service operator dashboard discovered by McAfee Labs researchers, showing victim counts, stolen credential summaries, and infected system profiles.

WeedHack’s operator dashboard, uncovered by McAfee Labs. A polished, professional interface for running a cybercrime operation, available to anyone with a Discord account. Source: McAfee

By the Numbers: The Scale of the WeedHack Campaign

Here's what the data shows.

These are not estimates or projections. This is data from a campaign, confirmed by McAfee Labs researchers who found the operation.

  • 116,464 computers infected since January 2026
  • 2,000–3,000 new infections added every single day
  • 3,820+ unique malicious files currently in circulation
  • 240+ separate URLs used to distribute the malware

The United States accounts for the largest share of infections, followed by Germany, India, the United Kingdom, Italy, Vietnam, Canada, Norway, Sweden, Finland, and Spain.

What makes WeedHack different from most cybercriminal operations is not its technical sophistication. It is its accessibility. Traditional malware tools cost hundreds of dollars per month on underground criminal networks, require technical knowledge to operate, and are designed for professional criminals after financial gain. WeedHack is designed for anyone with a grudge and an internet connection.

What Is Malware-as-a-Service (and Why It Changes Everything)

To understand WeedHack, you first need to understand the business model behind it. WeedHack is a Malware-as-a-Service (MaaS) operation. MaaS works exactly like any other software subscription service, think Netflix or Spotify, except the product is a hacking platform.

The people who built WeedHack are the developers. They created the infrastructure, wrote the code, and built the dashboard that operators use to manage their victims. Operators are the customers, the people who pay to use the platform and deploy the malware against targets of their choosing. The developer takes a cut; the operator gets a ready-made criminal toolkit without needing to understand a single line of code.

This separation of development from operation is what makes MaaS so dangerous. It used to be that launching a serious malware campaign required significant technical skill.

MaaS eliminates that barrier entirely. The technical expertise lives in the platform. The operator just needs to know who they want to target.

WeedHack takes this model further than almost any other documented MaaS operation. Not only is the premium tier priced at just $5 per month (less than most streaming services), but the basic version of the platform is completely free. Anyone with a Discord account can sign up, access a full operator dashboard, and immediately start distributing malware.

This is what makes WeedHack a turning point.

Every other MaaS operation has a financial barrier that filters out casual bad actors. WeedHack removed that filter entirely.

The result is a platform that is functionally accessible to anyone with a grudge (and that is a category of person that has always existed in large numbers).

What changed is not the motivation. What changed is the tool.

Screenshot showing WeedHack’s Malware-as-a-Service pricing tiers, illustrating the free tier and $5 per month premium tier with feature breakdowns.

WeedHack’s pricing structure: a fully functional free tier requiring only a Discord account, and a $5/month premium tier that adds webcam access, keylogging, and remote control. Source: McAfee

Screenshot showing WeedHack’s Malware-as-a-Service pricing tiers, illustrating the free tier and $5 per month premium tier with feature breakdowns.

WeedHack’s pricing structure: a fully functional free tier requiring only a Discord account, and a $5/month premium tier that adds webcam access, keylogging, and remote control. Source: McAfee

Free vs. Premium: What WeedHack Can Actually Do to Your Child’s Computer

The capabilities of WeedHack depend on which tier the attacker is using. Here is exactly what each tier can do, and what the real-world impact is on the child on the receiving end.

Feature Tier

What it Steals / Controls

Real World Impact

Free Tier

$0 (Discord account only)

Minecraft session IDs, cookies, saved passwords across 36 browsers, 56 crypto browser extensions, 12 desktop crypto wallets, Discord/Steam/Telegram credentials, system screenshots

Account theft, loss of gaming profiles, private messages exposed, crypto stolen

Premium Tier

$5/month or $24.99 lifetime

Everything in free tier, plus: live webcam streaming, keylogging (reads every keystroke in real time), full remote screen control with mouse and keyboard input, hidden remote file management

Total surveillance and extortion: attacker can watch victims through their own webcam, record passwords as they are typed, and extract private files for blackmail

Let that sink in for a moment. For the cost of a cup of coffee per month, a teenager with a grievance can access a tool that lets them watch another child through their own webcam, read every word they type, including passwords and private messages, and pull files from their computer to use as leverage. This is not a hypothetical capability. McAfee’s investigation found evidence that it was actively being used exactly this way.

The free tier is not a watered-down version either. Even without spending a single dollar, an attacker can steal Minecraft accounts, Discord tokens, Steam credentials, and saved passwords from 36 different browsers. For a teenager whose entire social life runs through Discord and whose gaming identity is built on their Minecraft account, losing these is genuinely devastating.

The Part Nobody Saw Coming: Teenagers Using WeedHack to Bully Their Classmates

Most malware campaigns are run by financially motivated criminals. They want bank credentials, crypto wallets, corporate login data, things they can turn into money. WeedHack attracted a very different kind of operator.

Inside the WeedHack ecosystem, McAfee researchers discovered a Telegram channel with more than 850 members. The activity they found there was not financial fraud. It was a trading floor for humiliation.

WeedHack Telegram Group

WeedHack’s Telegram community. Source: McAfee

WeedHack Telegram Group

WeedHack’s Telegram community. Source: McAfee

Teenagers and young adults in the channel were sharing stolen webcam footage of classmates, screenshots of private conversations pulled from hacked Discord accounts, and what researchers described as “trophies," evidence of successful attacks on people they knew personally. 

These were not random targets. They were people from the same schools, the same friend groups, the same gaming communities. The malware was being used as a weapon in personal conflicts, not as a tool for financial crime.

This is a pattern that cybersecurity researchers and child safety experts have been warning about for years: as hacking tools become cheaper and easier to use, the barrier to entry for peer-to-peer digital attacks drops to near zero.

You no longer need to understand how malware works to deploy it. You just need a reason to want to hurt someone, and that is something teenagers have always had in abundance.

This is the profile of the new teen hacker: not a coding prodigy in a basement, but a 15-year-old with a Discord account, a $5 subscription, and a grievance against someone they sit next to in class.

The extortion dynamic is particularly concerning. Once an attacker has webcam footage of a classmate, screenshots of private messages, or embarrassing files pulled from a hacked computer, they have leverage. They can demand money, demand silence, or demand that the victim do or stop doing something. 

And because the victim is a teenager who downloaded what they thought was a legitimate Minecraft mod, they are often too embarrassed or scared to tell an adult what happened.

Screenshot of the WeedHack operator Telegram channel, with identifying information blurred, showing members sharing evidence of attacks and stolen material from victims.

Inside WeedHack’s Telegram community: 850+ members sharing stolen footage and “trophies” of successful attacks on classmates. Source: McAfee

Screenshot of the WeedHack operator Telegram channel, with identifying information blurred, showing members sharing evidence of attacks and stolen material from victims.

Inside WeedHack’s Telegram community: 850+ members sharing stolen footage and “trophies” of successful attacks on classmates. Source: McAfee

Anatomy of the Trap: How WeedHack Finds Its Victims

WeedHack does not arrive on your child’s computer uninvited. It gets there because your child downloaded what looked like something they wanted. Understanding exactly how that happens is the first step to preventing it.

Vector 1: The YouTube Bait

YouTube is the primary distribution channel for WeedHack. Attackers create channels, sometimes many of them in parallel, and post well-produced videos showing off free Minecraft mods, custom game clients, performance-boosting tools, or cheat utilities. The titles lean into the exact language players search for: free mods, client downloads, and Minecraft hacks, a catch-all term players use for gameplay shortcuts and cheats, and one that WeedHack's operators exploit because it draws high search traffic from the exact audience they are targeting.

Some of these videos are genuinely well-made, complete with voice-over narration, clean screen recordings, and convincing demonstrations of the tool working correctly. Some videos in the WeedHack campaign accumulated more than 7,500 views before being flagged.

The trap is in the description. Attackers drop malicious download links in the video description and comments section, sometimes buried among what appear to be positive reviews from other accounts, which are also controlled by the attacker.

A child watching a YouTube video about a free Minecraft mod sees exactly what they expect to see: a product that works, comments from people who like it, and a download link. The malware hides inside a file that looks like a standard Minecraft .JAR file (the format Minecraft legitimately uses for mods and plugins).

Once that file runs, the damage begins before the child realizes anything is wrong. The malware disables Windows Defender, collects system information, and drops additional payloads that establish persistent access. The child’s computer is compromised. The child may still be watching the YouTube video, unaware.

Screenshot of a fake Minecraft mod YouTube video used to distribute WeedHack malware, showing a polished video with view count and a link in the description pointing to a malicious download.

A WeedHack distribution video on YouTube: well-edited, professional-looking, with a malicious download link in the description. Some of these accumulated more than 7,500 views. Source: McAfee

Screenshot of a fake Minecraft mod YouTube video used to distribute WeedHack malware, showing a polished video with view count and a link in the description pointing to a malicious download.

A WeedHack distribution video on YouTube: well-edited, professional-looking, with a malicious download link in the description. Some of these accumulated more than 7,500 views. Source: McAfee

Vector 2: SEO Poisoning (When Google Becomes the Weapon)

Search engine optimization (SEO) is the set of techniques that website owners use to get their sites to appear higher in Google search results. SEO poisoning is what happens when attackers use those same techniques to push malicious sites to the top of results for searches that have nothing to do with crime.

A screenshot of an SEO poisoning how-to-guide hosted on the WeedHack website.

An SEO poisoning how-to-guide hosted on the WeedHack website. Source: McAfee

A screenshot of an SEO poisoning how-to-guide hosted on the WeedHack website.

An SEO poisoning how-to-guide hosted on the WeedHack website. Source: McAfee

Here is how WeedHack’s operators used SEO poisoning. Attackers identified real, legitimate Minecraft mods (tools with genuine user bases that players were actively searching for online). They then built fake websites that mimicked the legitimate download pages for those mods, down to the branding, screenshots, and download buttons.

They applied SEO techniques to push those fake sites up the search rankings. When a child searched Google for “[mod name] free download”, the fake site appeared at or near the top of the results.

The child clicked. The site looked exactly like the real one. The download button worked. The file that came down was a trojanized version of the mod. One that contained the real mod’s functionality alongside WeedHack’s payload, so everything appeared to work correctly after installation.

This attack is particularly difficult to defend against through education alone, because the child did everything right. They searched for a specific, named product. They found what appeared to be the official site. The mod worked.

There was no obvious sign that anything was wrong. The infection happened silently, in the background, while the child played Minecraft.

Screenshot of a malicious website created by WeedHack operators to mimic a legitimate Minecraft mod download page, used as part of the SEO poisoning distribution method.

A WeedHack lookalike site mimicking a legitimate Minecraft mod download page. Indistinguishable from the real thing, and appearing at the top of Google results through SEO poisoning. Source: McAfee

Screenshot of a malicious website created by WeedHack operators to mimic a legitimate Minecraft mod download page, used as part of the SEO poisoning distribution method.

A WeedHack lookalike site mimicking a legitimate Minecraft mod download page. Indistinguishable from the real thing, and appearing at the top of Google results through SEO poisoning. Source: McAfee

The Technical Trick: DonutDupe.JAR and How the Infection Spreads

When a victim downloads a WeedHack payload, they receive a file called DonutDupe.jar. The .JAR format is a standard Java archive, the same format Minecraft legitimately uses for mods, which is part of why it raises no immediate suspicion.

Once DonutDupe.jar executes, it kicks off a chain of events designed to maximize the attacker’s access while minimizing the chance of detection. First, it disables Windows Defender, removing the computer’s built-in protection. Then it collects basic system information and sends it to the attacker’s dashboard.

Then it drops two additional payloads: one that establishes persistence (meaning the malware survives reboots and keeps running in the background), and one that enables the remote access features depending on which tier the attacker has purchased.

WeedHack’s operator dashboard is hosted on what security researchers call the “clear net," the regular internet, not the dark web. This is unusual for criminal infrastructure and means the platform can be accessed from any browser without specialized software.

The dashboard gives operators a real-time view of their victims: which systems are infected, what data has been stolen, and remote control options. It supports Minecraft versions 1.21.0 through 1.21.10, the current versions most players are running.

The Parent Action Plan: How to Protect Your Child Right Now

The threat is real and active. Here is what to do about it.

Rule 1: Only download Minecraft mods from vetted platforms

This is the single most important thing you can establish in your household. Minecraft mods should only ever come from two sources:

  • CurseForge: the industry standard for safe, heavily moderated Minecraft mods and add-ons. Mods on CurseForge are reviewed before publication and are tied to verified developer accounts.
  • Modrinth: an open-source alternative with a strong security reputation and rigorous verification processes for submitted mods.

No YouTube link. No Google result that leads to an unfamiliar site. No file shared in a Discord server or by a friend. No exceptions.

Make this a rule your child understands before they understand why it matters. The explanation can come later. The rule needs to come first.

If your child insists a particular mod is only available somewhere other than CurseForge or Modrinth, that is the answer. It does not come into the house. The mod, however appealing, is not worth the risk.

Rule 2: Never disable antivirus software to install a game file

This is a red flag so significant that it deserves its own rule. WeedHack’s payloads, like many malicious Minecraft mods, are often flagged by antivirus software. The fake sites and YouTube videos distributing them frequently include instructions telling users to disable their antivirus before installing, because the file is “benign” and the antivirus is “giving a false positive.”

This is one of the most reliable warning signs that a file is malicious. Legitimate software does not require you to disable your security protection to install it. If any website, video, or instruction says to turn off Windows Defender or any antivirus software before running a file, stop immediately and do not proceed. The antivirus flagged it because it is dangerous.

Rule 3: Know the warning signs of an infection

WeedHack is designed to run silently in the background, but infections often leave detectable traces. Watch for these signs on your household computers:

  • A sudden, unexplained drop in computer performance or responsiveness
  • Unusually high CPU or RAM usage when no demanding applications are open (check Task Manager on Windows)
  • The computer’s webcam light activating unexpectedly when no video application is open
  • Unusual or unfamiliar processes running in the background
  • Discord, Steam, or gaming account notifications your child did not trigger — particularly password reset emails or logins from unfamiliar locations
  • Your child mentioning that their Minecraft account or Discord account “stopped working” or that they were logged out unexpectedly

Rule 4: Have the extortion conversation before it is needed

This is the conversation most parents never have because they assume their child will never face this situation. They are wrong, and the statistics on WeedHack prove it.

Your child needs to know, explicitly and in advance, what to do if someone messages them claiming to have hacked their computer, claiming to have webcam footage of them, or threatening to share private information unless they pay money or comply with demands. The answer is always the same: do not pay, do not comply, and tell a trusted adult immediately.

Paying does not make extortion stop. It proves to the attacker that the victim is willing to pay, which makes them a more attractive target for further demands. Complying with non-financial demands, sending more footage, recruiting other victims, and staying silent deepens the trap rather than escaping it. The only way out is to tell someone and involve the authorities.

Paying does not make extortion stop. It proves to the attacker that the victim is willing to pay, which makes them a more attractive target for further demands. Complying with non-financial demands, sending more footage, recruiting other victims, and staying silent deepens the trap rather than escaping it. The only way out is to tell someone and involve the authorities.

Rule 5: Audit what is already on your devices

If your child plays Minecraft and has downloaded mods in the past, it is worth doing a basic check of what is on the computer. Scan for unfamiliar processes, check the Task Manager for high CPU usage, and run a full scan with updated antivirus software. If you suspect an infection, do not just delete the suspicious file. WeedHack establishes persistence, meaning it reinstalls itself after deletion. A full system wipe and reinstall may be necessary.

McAfee has noted that its Web Protection tools actively block the sites distributing WeedHack. If you do not have active antivirus protection on the computers your children use, this is a reasonable moment to reconsider that.

The Bigger Picture: Why WeedHack Is a Warning, Not an Isolated Incident

WeedHack is not the first Malware-as-a-Service targeting young gamers, and it will not be the last. It is the most clearly documented example of a trend that has been building for years: the democratization of cybercrime.

For decades, the barrier to hacking was technical skill. You needed to understand programming, networking, and system architecture to do meaningful damage. That barrier protected most potential victims, because most would-be attackers lacked the knowledge to become real threats.

MaaS has eliminated that barrier. Today, the technical skill lives in the platform.

The operator just needs motivation and a credit card, or in WeedHack’s case, not even that. The result is a threat landscape in which virtually anyone can become an attacker, and teenagers, who have always had abundant motivation to hurt people they are in conflict with, are increasingly in that category.

The WeedHack campaign is also a reminder that digital threats to children are not exclusively about adult predators. The cyberbullying facilitated by WeedHack, the stolen webcam footage, the leaked private messages, the extortion campaigns running through Telegram channels were perpetrated almost entirely by other teenagers. The danger is not just outside the peer group. It can be inside it.

McAfee researcher Aayush Tyagi, who led the WeedHack investigation, summarized the core shift:

 WeedHack is a Malware-as-a-Service (MaaS) campaign, meaning it’s a criminal business that sells hacking tools to customers, the same way a legitimate software company sells subscriptions.

That framing matters. This is not a rogue hacker operating in isolation. It is a business. It has a pricing page, a feature list, a support channel, and a customer base.

And its customers, at least the ones McAfee’s researchers found in the Telegram community, include teenagers who attend the same schools as your child.

What This Means for Parents Using Standard Parental Controls

Parents who already have monitoring tools in place (screen time limits, content filters, app blockers) may feel a false sense of security reading about WeedHack. Those tools address a different category of risk. They cannot see a WeedHack infection.

Standard parental controls work at the app layer. They can block websites, limit screen time, and filter content.

They cannot detect malware running silently in the background. They cannot tell you that a process called DonutDupe.jar is extracting your child’s Discord credentials and sending them to a dashboard in another country. They cannot show you that your child’s webcam was activated remotely at 11 pm.

WeedHack’s payload operates below the level where app-layer monitoring tools function. It disables Windows Defender on installation, the same mechanism that app-layer tools rely on for real-time protection. By the time a standard parental control app might notice something unusual, the infection has already established persistence and exfiltrated the most valuable data.

This is the same architectural gap that exists in every app-layer solution: they are tenants in a system they do not control, and a sufficiently determined attacker (or a sufficiently malicious piece of software) can operate in the spaces they cannot see.

Aqua One’s OS-level monitoring addresses a related but distinct dimension of this problem. Because Aqua One captures what appears on screen at the system level, below every app, a parent can see what their child is doing in real time, including any communications or activity that would otherwise be hidden inside encrypted apps or disappearing messages.

If a WeedHack attacker were using their access to communicate with an Aqua One user’s child through Discord, Snapchat, or WhatsApp, those communications would be visible in Instant Replay, regardless of whether they were encrypted, disappearing, or happening in a “private” mode.

The combination of OS-level visibility into your child’s activity and educated vigilance about what gets downloaded onto shared household computers is the most complete protection currently available.

Quick Reference: The WeedHack Parent Checklist

  • Only allow Minecraft mod downloads from CurseForge or Modrinth. No YouTube links, no unfamiliar sites.
  • Never disable antivirus software to install a game file. Any instruction to do so means the file is malicious.
  • Run a full antivirus scan on household computers your child uses for Minecraft, particularly if they have downloaded mods in the past.
  • Check Task Manager for unusual processes or high CPU usage at idle.
  • Watch for the webcam light activating when no video app is open.
  • Have the extortion conversation with your child now, before it is needed: do not pay, do not comply, tell a trusted adult immediately.
  • If you suspect an infection, do not just delete suspicious files; WeedHack reinstalls itself. A full wipe may be necessary.
  • Consider active antivirus protection (McAfee Web Protection specifically blocks WeedHack distribution sites).
  • Know that standard parental controls cannot detect or block malware — they address a different category of risk.

Frequently Asked Questions

What is WeedHack?

WeedHack is a Malware-as-a-Service (MaaS) operation targeting Minecraft players. Discovered by McAfee Labs in June 2026, it has infected more than 116,000 computers since January 2026 by disguising itself as free Minecraft mods, cheat clients, and game utilities. It is unusual among malware campaigns for offering a fully functional free tier requiring only a Telegram account, with a premium tier available for $5 per month.

How does Minecraft malware get onto a computer?

WeedHack spreads through two primary methods: YouTube videos promoting fake Minecraft mods with malicious download links in the description, and SEO poisoning — creating fake lookalike websites for legitimate mods and manipulating Google search results to push them to the top. The payload arrives as a .JAR file, the same format Minecraft legitimately uses for mods, making it difficult to identify as suspicious.

What is SEO poisoning?

SEO poisoning is an attack method where criminals use search engine optimization techniques to push malicious websites to the top of search results for legitimate queries. In WeedHack’s case, attackers built fake websites mimicking official Minecraft mod download pages and used SEO techniques to make them appear above the real sites when children searched for specific mods. The fake site looked identical to the real one, and the file it delivered contained both the genuine mod and the malware payload.

What is keylogging?

Keylogging is a form of surveillance in which software records every keystroke a person types on their keyboard, including passwords, private messages, credit card numbers, and anything else entered on the computer. WeedHack’s premium tier includes a keylogger, meaning an attacker with premium access can read everything a victim types in real time, without the victim knowing. This is how attackers using WeedHack’s premium tier can obtain passwords for accounts even if those accounts were not already logged in when the infection occurred.

Are safe Minecraft mods available? Where should I download them?

Yes. CurseForge and Modrinth are the two platforms endorsed by the Minecraft community and cybersecurity researchers for safe mod downloads. Both platforms review mods before publication and require verified developer accounts.

Any mod available on these platforms has passed a moderation process. Mods downloaded from YouTube links, unfamiliar websites, or peer-to-peer sharing have not, and should not be installed.

What should my child do if someone threatens them with WeedHack footage or data?

Do not pay. Do not comply with demands. Tell a trusted adult immediately. Paying an extortion demand does not end the extortion; it confirms to the attacker that the victim will pay, making them a more valuable target for continued demands.

The correct response is to involve a parent or guardian, who can then contact school administrators if the attacker is a classmate, and report the incident to local law enforcement. Keep records of any threatening messages received.

Can parental controls protect against WeedHack?

Standard app-layer parental controls (content filters, screen time limits, app blockers) cannot detect or block WeedHack. The malware operates at a system level below where those tools function, and it disables Windows Defender on installation. The most effective protection against WeedHack specifically is a strict rule about where Minecraft mods can be downloaded from, combined with active antivirus software that has updated threat definitions.

At Cyber Dive, we research the platforms and tools your kids are using so you do not have to figure it out alone. If this was useful, share it with a parent who needs it.

Worried if an app is safe for your kid?

We break it down. No fluff. No sugarcoating. Just the truth.

📲 Deep dives on trending apps
⚠️ Real risks, no hype
​🚨 Get alerts when new guides drop

Drop your email. Stay ahead. Protect your family.

Jordan Arnold

Kansas-born, digital native on a mission to help parents decode the online world their kids actually live in. When I’m not swimming laps or obsessing over the perfect Eastern European train route, I’m dodging judgmental stares from my bald, bossy cat, who’s absolutely convinced he should be in charge (and he might not be wrong).

 Type 2 Helper / INTJ Architect

Cyber Dive

© 2026 Cyber-Dive Corp.​