How to remove WeedHack malware from the operating system

Trojan

Also Known As: WeedHack malware-as-a-service

Damage level:

Get free scan and check if your device is infected.

Remove it now

To use full-featured product, you have to purchase a license for Combo Cleaner. Seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

What kind of malware is WeedHack malware?

WeedHack malware is a Malware-as-a-Service (MaaS) campaign that combines an information stealer with Remote Access Trojan (RAT) features, and distributes both through fake Minecraft mods and game client programs.

According to research published by McAfee Labs, the campaign has been active since January 2026 and specifically targets Minecraft players who download community-made tools from unverified sources.

Two subscription tiers are on offer. The free version steals browser credentials, cryptocurrency wallet data, and Minecraft session tokens. The paid tier - starting at $5 per month - adds live remote control, webcam access, keylogging, and file management capabilities.

WeedHack Malware detections on VirusTotal

WeedHack Malware overview

WeedHack is operated through a web-based dashboard that anyone can access with a Discord account and an internet connection. Since launching in January 2026, the campaign has logged over 116,000 total infections, averaging roughly 2,000 to 3,000 new hits per day across more than 240 distribution URLs.

The dashboard lets paying customers view statistics, browse stolen credentials, configure Telegram or Discord notifications for new infections, and download custom-built payloads. A leaderboard ranks customers by infection count and is refreshed every ten minutes.

Tutorial content is baked directly into the dashboard, covering distribution tactics such as YouTube promotion and SEO poisoning, instructions for using stolen credentials, and operational security guidelines for customers. McAfee Labs found 10 domains hosting the dashboard and identified 11 additional domains previously used by the same threat actor in similar campaigns.

The campaign has drawn a notably young audience. McAfee Labs observed that many customers appear to be teenagers, and the platform's Telegram channel, which had over 850 members at the time of research, has been used to share footage of victims being harassed via their own webcams.

WeedHack's stealer capabilities

Even the free tier is a capable stealer. On first execution, WeedHack collects system information including CPU, GPU, RAM, operating system, IP address, username, and PC name, and captures a screenshot of the victim's desktop.

Saved passwords and cookies are exported from 36 different web browsers. Session tokens from Discord, Steam, and Telegram are grabbed separately. A file-search module can locate and exfiltrate files matching any of 24 built-in keywords.

Minecraft players face a specific threat: WeedHack steals session IDs from the game itself and from four popular Minecraft launchers. These tokens can be used to hijack a Minecraft account without knowing the account password.

On the cryptocurrency side, 56 browser-based wallet extensions and 12 desktop wallet applications are targeted. Stolen wallet access may allow the attacker to drain funds without triggering any alert visible to the victim.

WeedHack's remote access features

Premium subscribers gain full remote control on top of the stealer functionality. A live screen-sharing module lets operators view and interact with the victim's desktop using keyboard and mouse input in real time.

A webcam module captures footage without the victim's knowledge. Keylogging records every key typed after infection, including passwords entered into accounts not yet compromised. Reverse shell access lets the attacker run arbitrary commands on the machine. File management tools allow operators to browse, upload, and download files at will.

Evasion and infrastructure

WeedHack uses a technique called EtherHiding to protect its command-and-control (C2) infrastructure. Rather than embedding a fixed server address in the code, the malware fetches its current C2 domain from the Ethereum blockchain. Blockchain entries are far harder to remove than conventional web servers, making it difficult to shut down the campaign even when individual domains are detected and blocked.

Responses from the C2 are RSA-signed and verified by the malware before execution, protecting the campaign's network from takeover attempts by outside parties.

The payload is distributed as a JAR file. Operators can inject WeedHack into a functioning Minecraft mod using a build tool on the dashboard, so the mod appears to work normally while the malware runs in the background.

Threat Summary:
Name WeedHack malware-as-a-service
Threat Type Remote Access Trojan (RAT), Information Stealer, Malware-as-a-Service (MaaS)
Detection Names Avast (Win32:MalwareX-gen [Trj]), Combo Cleaner (Gen:Heur.MSIL.Bladabindi.1), ESET-NOD32 (MSIL/Kryptik.AQAT Trojan), Kaspersky (HEUR:Trojan-PSW.Win32.Stealer.gen), Microsoft (Trojan:MSIL/Stealer!MTB), Full List (VirusTotal)
Symptoms Remote Access Trojans and information stealers are designed to stealthily infiltrate the victim's computer and remain silent, and thus no particular symptoms are clearly visible on an infected machine.
Distribution methods Malicious Minecraft mod and client files (JAR format), fake mod distribution websites, YouTube videos, SEO poisoning.
Damage Stolen passwords and banking information, identity theft, Minecraft account hijacking, cryptocurrency theft, remote device control, webcam surveillance, keylogging, additional infections, monetary loss.
Malware Removal (Windows)

To eliminate possible malware infections, scan your computer with legitimate antivirus software. Our security researchers recommend using Combo Cleaner.

Download Combo Cleaner

To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Conclusion

WeedHack Malware puts Minecraft players at serious risk. Its free tier strips away browser passwords, cryptocurrency wallet contents, game account tokens, and credentials from Discord, Steam, and Telegram - all without producing any visible warning on the infected machine.

The paid tier escalates the threat to full device surveillance. Attackers can watch the victim's screen, record them through their webcam, log every keystroke, and access files on the system. McAfee Labs has documented the malware being used for targeted cyberbullying and account harassment. Any device suspected of running WeedHack should be scanned and cleaned immediately.

More examples of malware classified as a Remote Access Trojan are Heisenberg, TONResolver, and QuimaRAT.

How did WeedHack Malware infiltrate my computer?

WeedHack spreads mainly through YouTube. McAfee Labs identified two YouTube channels posting videos that appear to review or demonstrate Minecraft mods and clients, with links to malicious download sites placed in both the video description and comment section.

The campaign also relies on SEO poisoning. Threat actors target popular Minecraft clients and mods that lack an official website and are normally hosted on platforms like GitHub. By building convincing standalone sites and promoting them through Discord and Reddit discussions, they push malicious pages to the top of search results.

The fake websites are professionally designed. One site posed as a catalog offering multiple Minecraft tools, including Radium Client, each displayed with fabricated download counts and ratings. A second presented itself as an item duplicator mod for the DonutSMP multiplayer server, complete with invented player reviews. Some sites even linked to the real Discord servers and GitHub repositories of the tools they impersonated, to appear trustworthy.

The malware is delivered as a JAR file. Victims who download what appears to be a Minecraft mod are actually executing WeedHack. Because operators can inject the malware into a working mod file using the dashboard's build tool, the mod may still function normally, leaving the victim with no immediate reason for suspicion. McAfee Labs uncovered over 3,820 unique malicious JAR files and more than 240 distribution URLs tied to this campaign.

How to avoid installation of malware?

Only download Minecraft mods, clients, and tools from the official developer's website or a well-established platform such as Modrinth or CurseForge. YouTube videos linking to third-party download sites are a common distribution vector for malware. Never disable your antivirus at a website's request - legitimate software does not require this.

Keep your operating system and installed software up to date, and run regular scans with a reputable security tool. Avoid pirated software, key generators, and cracks, as these are frequent carriers of malware. If you believe that your computer is already infected, we recommend running a scan with Combo Cleaner Antivirus for Windows to automatically eliminate infiltrated malware.

YouTube video used to distribute WeedHack Malware (source: mcafee.com):

YouTube video used to distribute WeedHack Malware

Fake websites distributing malicious installers containing WeedHack Malware (source: mcafee.com):

Sample 1:

Fake website distributing WeedHack Malware 1

Sample 2:

Fake website distributing WeedHack Malware 2

Screenshot of WeedHack malware's admin panel:

WeedHack Malware administration panel

Instant automatic malware removal:

Manual threat removal might be a lengthy and complicated process that requires advanced IT skills. Combo Cleaner is a professional automatic malware removal tool that is recommended to get rid of malware. Download it by clicking the button below:

DOWNLOAD Combo Cleaner

By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for Combo Cleaner. 7 days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.

Quick menu:

How to remove malware manually?

Manual malware removal is a complicated task - usually it is best to allow antivirus or anti-malware programs to do this automatically. To remove this malware we recommend using Combo Cleaner Antivirus for Windows.

If you wish to remove malware manually, the first step is to identify the name of the malware that you are trying to remove. Here is an example of a suspicious program running on a user's computer:

Malware process running in the Task Manager

If you checked the list of programs running on your computer, for example, using task manager, and identified a program that looks suspicious, you should continue with these steps:

manual malware removal step 1Download a program called Autoruns. This program shows auto-start applications, Registry, and file system locations:

Autoruns application appearance

manual malware removal step 2Restart your computer into Safe Mode:

Windows XP and Windows 7 users: Start your computer in Safe Mode. Click Start, click Shut Down, click Restart, click OK. During your computer start process, press the F8 key on your keyboard multiple times until you see the Windows Advanced Option menu, and then select Safe Mode with Networking from the list.

Run Windows 7 or Windows XP in Safe Mode with Networking

Video showing how to start Windows 7 in "Safe Mode with Networking":

Windows 8 users: Start Windows 8 is Safe Mode with Networking - Go to Windows 8 Start Screen, type Advanced, in the search results select Settings. Click Advanced startup options, in the opened "General PC Settings" window, select Advanced startup.

Click the "Restart now" button. Your computer will now restart into the "Advanced Startup options menu". Click the "Troubleshoot" button, and then click the "Advanced options" button. In the advanced option screen, click "Startup settings".

Click the "Restart" button. Your PC will restart into the Startup Settings screen. Press F5 to boot in Safe Mode with Networking.

Run Windows 8 in Safe Mode with Networking

Video showing how to start Windows 8 in "Safe Mode with Networking":

Windows 10 users: Click the Windows logo and select the Power icon. In the opened menu click "Restart" while holding "Shift" button on your keyboard. In the "choose an option" window click on the "Troubleshoot", next select "Advanced options".

In the advanced options menu select "Startup Settings" and click on the "Restart" button. In the following window you should click the "F5" button on your keyboard. This will restart your operating system in safe mode with networking.

Run Windows 10 in Safe Mode with Networking

Video showing how to start Windows 10 in "Safe Mode with Networking":

manual malware removal step 3Extract the downloaded archive and run the Autoruns.exe file.

Extract Autoruns.zip archive and run Autoruns.exe application

manual malware removal step 4In the Autoruns application, click "Options" at the top and uncheck "Hide Empty Locations" and "Hide Windows Entries" options. After this procedure, click the "Refresh" icon.

Refresh Autoruns application results

manual malware removal step 5Check the list provided by the Autoruns application and locate the malware file that you want to eliminate.

You should write down its full path and name. Note that some malware hides process names under legitimate Windows process names. At this stage, it is very important to avoid removing system files. After you locate the suspicious program you wish to remove, right click your mouse over its name and choose "Delete".

Delete malware in Autoruns

After removing the malware through the Autoruns application (this ensures that the malware will not run automatically on the next system startup), you should search for the malware name on your computer. Be sure to enable hidden files and folders before proceeding. If you find the filename of the malware, be sure to remove it.

Search for malware and delete it

Reboot your computer in normal mode. Following these steps should remove any malware from your computer. Note that manual threat removal requires advanced computer skills. If you do not have these skills, leave malware removal to antivirus and anti-malware programs.

These steps might not work with advanced malware infections. As always it is best to prevent infection than try to remove malware later. To keep your computer safe, install the latest operating system updates and use antivirus software. To be sure your computer is free of malware infections, we recommend scanning it with Combo Cleaner Antivirus for Windows.

Frequently Asked Questions (FAQ)

My computer is infected with WeedHack Malware, should I format my storage device to get rid of it?

Formatting removes WeedHack Malware, but it also wipes every file on the drive. A reputable security tool such as Combo Cleaner should be tried first, as it can eliminate the malware without destroying your data.

What are the biggest issues that WeedHack Malware can cause?

WeedHack Malware can steal browser passwords, session tokens for Discord, Steam, and Telegram, Minecraft account credentials, and cryptocurrency wallet contents. The premium tier also hands the attacker live control over your device - including webcam access and keylogging. This can result in account hijacking, identity theft, and loss of funds.

What is the purpose of WeedHack Malware?

The free tier is built to steal credentials - browser passwords and cookies, cryptocurrency wallet data, Minecraft session tokens, and app credentials from Discord, Steam, and Telegram. The premium tier adds remote access so operators can watch the screen, capture webcam footage, log keystrokes, and manage files on the victim's system.

How did WeedHack Malware infiltrate my computer?

WeedHack Malware reaches victims primarily through YouTube videos that appear to review Minecraft mods and clients, with download links pointing to malicious sites. SEO poisoning is also used to place fake mod websites at the top of search results.

Victims who click through and download receive a malicious JAR file. McAfee Labs identified over 3,820 unique malicious JAR files and more than 240 distribution URLs tied to this campaign.

Will Combo Cleaner protect me from malware?

Yes. Combo Cleaner can detect and remove most known malware. Because high-risk threats can embed themselves deeply in the system, running a full scan is the safest way to confirm the device is entirely clean.

Share:

facebook
X (Twitter)
linkedin
copy link
Tomas Meskauskas

Tomas Meskauskas

Expert security researcher, professional malware analyst

I am passionate about computer security and technology. I have an experience of over 10 years working in various companies related to computer technical issue solving and Internet security. I have been working as an author and editor for pcrisk.com since 2010. Follow me on Twitter and LinkedIn to stay informed about the latest online security threats.

▼ Show Discussion

PCrisk security portal is brought by a company RCS LT.

Joined forces of security researchers help educate computer users about the latest online security threats. More information about the company RCS LT.

Our malware removal guides are free. However, if you want to support us you can send us a donation.

Donate