Cybersecurity researchers report a large malware campaign targeting Minecraft players using a service dubbed WeedHack. The campaign, attributed to a malware-as-a-service operation, has been active since January 2026 and has infected more than 116,000 systems, with additional infections continuing over time.

Multiple outlets describe how the attackers distribute malicious payloads by impersonating Minecraft clients and mods. Fake downloads are promoted online, including through SEO poisoning and advertisements on YouTube, where threat actors push users toward counterfeit “mods” or related tools. Once installed, the malware is designed to steal information and enable remote access capabilities. Researchers say it can provide threat actors with access to victim systems and may collect data such as files, while also enabling access to elements of the victim’s environment including screen and webcam feeds.

The reporting across sources is consistent on the campaign name, its focus on Minecraft users, the distribution methods involving SEO/YouTube-based lures, and the reported scale of infections since January 2026.