Top Google Results for Minecraft Client Led Gamers to Malware, McAfee Finds

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Minecraft players searching for a popular client can now land on malware instead of a game tool. A renewed WeedHack campaign is using poisoned search results, copied websites and free-download lures to place dangerous Java files in front of players.

The risk is not limited to one fake page. Attackers are cloning branding, feature lists, installation guides and even links to real GitHub projects, making fraudulent Minecraft client sites look convincing at a glance.

Downloads delivered through those pages carry the WeedHack payload. McAfee analysts identified the continuing activity after the campaign’s original command-and-control infrastructure was disrupted.

The group’s dashboard is down, but its distribution network remains active, showing how quickly a malware operation can change its delivery methods.

glazed-client landing page (Source - McAfee)
glazed-client landing page (Source – McAfee)

The scale is notable. McAfee WebAdvisor blocked more than 6,300 attempts to reach the malicious sites in the past month, while an earlier investigation linked WeedHack to more than 116,464 infected gamers.

McAfee said in a report shared with Cyber Security News (CSN) that the campaign illustrates why a high-ranking result should not be treated as proof that a download is safe.

Top Google Results for Minecraft Client Led Gamers

Researchers found that the first two Google results for searches for Xenon Client directed users to WeedHack-spreading sites.

This is a clear example of SEO poisoning, where criminals manipulate search visibility so that a fake download page appears before, or alongside, legitimate project resources.

One of the sites, xenoclient.lol, offered free and premium options, complete with download and installation pages, FAQs, credits and a link to Xenon Client’s genuine GitHub repository.

radium-client landing page (Source - McAfee)
radium-client landing page (Source – McAfee)

Another, xenonclient.com, promoted a free version of the client. Both were designed to turn a familiar search into a malware delivery route.

Other impersonation sites copied Glazed Client, Radium Client, SeedCrackerX, Nova Client, Meteor Client and 22qq-client.

In some cases, operators targeted projects without an official standalone website, exploiting the gap to outrank legitimate GitHub or mod-platform listings. A Minecraft malware loader investigation shows the broader danger of trojanized game files that appear useful to players.

The researchers also found a malicious Krypton Client page built with lovable.app, an AI-powered site-building service, underscoring how easily attackers can produce polished pages at speed.

Comparable fake download SEO campaigns have used the same trust gap outside gaming. Several pages advertised paid clients or cheats for free, while others offered many version choices that all led to infected files. The apparent choice keeps visitors inside the same malicious distribution chain.

Familiar Platforms Extend the Trap

The campaign does not rely only on lookalike domains. Of the malicious URLs McAfee identified, 49.6% were Discord links, 23.4% MediaFire links, 8.2% GitHub links and 4.6% Dropbox links.

These widely used services can make a malicious file seem less suspicious when it is shared in community chats or repositories. Researchers also observed tainted downloads hosted through community sites, including Planet Minecraft and EndMods.

Links can then be promoted through Discord, Reddit and other online spaces, widening the audience beyond users who arrive through a search engine. The approach echoes YouTube and search poisoning abuse that previously drove Minecraft players toward WeedHack.

The safest response is to start with the project’s verified developer page or a reputable mod platform, rather than choosing the first search result.

Google search results for ‘Xenon Client’ (Source - McAfee)
Google search results for ‘Xenon Client’ (Source – McAfee)

Players should compare the full URL carefully, avoid cracked or supposedly free premium clients, and treat a request to disable security software as a serious warning sign.

Downloaded JAR files, mods, installers and archives should be scanned before they are opened, even when they came from a popular-looking community.

If a security tool flags a file, stop and investigate instead of assuming the alert is wrong. Keeping the operating system, browser, games and security tools updated also reduces exposure to known weaknesses.

For families and server communities, the practical lesson is simple: share verified download locations and report lookalike pages quickly.

A fake Minecraft mods threat demonstrates why a promised gameplay advantage can have consequences far beyond a single compromised account.

Indicators of compromise (IoCs):-

Type Indicator Description
Malicious URL hxxps://glazed-client.com/ Lookalike Glazed Client website distributing WeedHack
Malicious repository hxxps://github.com/Hl3n/GambleRigMod GitHub repository associated with WeedHack distribution
Malicious URL hxxps://www.radium-client.com/ Fake Radium Client download website
Discord channel hxxps://discord.com/channels/1467145812906872834/ EasyClients Discord channel linked to infected clients
Malicious URL hxxps://seedcrackerx.github.io/ Fake SeedCrackerX website hosting infected downloads
Malicious repository hxxps://github.com/seedcrackerx/seedcrackerx.github.io GitHub repository associated with fake SeedCrackerX site
Malicious URL hxxps://xenonclient.com/ Fake Xenon Client website distributing WeedHack
Malicious URL hxxps://xenoclient.lol Xenon Client impersonation website distributing WeedHack
Malicious URL hxxps://nova-client.com/ Fake Nova Client download website
Malicious URL hxxps://cheatlib.xyz/ Website offering WeedHack-infected Minecraft mods
Discord channel hxxps://discord.com/channels/1478170973755936990 CheatLib Discord channel associated with infected mods
Malicious domain hxxps://meteorclients.com Fake Meteor Client download website
Malicious URL hxxp://22qq-client.com/ Fake 22qq-client website distributing an infected JAR file
Malicious URL hxxps://kryptonclientcrack.lovable.app Fake cracked Krypton Client website
Malicious repository hxxps://github.com/lsellh/ GitHub repository associated with WeedHack distribution
Malicious file URL hxxps://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar WeedHack-infected Minecraft mod download
Malicious file URL hxxps://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jar WeedHack-infected Minecraft mod download
Malicious file URL hxxps://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip Active WeedHack-distributing ZIP archive

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post Top Google Results for Minecraft Client Led Gamers to Malware, McAfee Finds appeared first on Cyber Security News.