🎯 Contexte
Source : Cryptika (relayant CyberSecurityNews), publié le 25 août 2026. McAfee a publié un rapport détaillant la campagne WeedHack, une opération de distribution de malware ciblant les joueurs Minecraft via l’empoisonnement de résultats de recherche Google (SEO poisoning).
🔍 Mécanisme d’attaque
Les attaquants clonent des sites officiels de clients Minecraft populaires (Xenon Client, Glazed Client, Radium Client, Nova Client, Meteor Client, SeedCrackerX, 22qq-client, Krypton Client) en reproduisant fidèlement :
- Les pages de téléchargement et d’installation
- Les FAQ et crédits
- Les liens vers les dépôts GitHub légitimes
Les faux sites sont positionnés en tête des résultats Google, notamment les deux premiers résultats pour la recherche « Xenon Client ». Un site malveillant a même été construit via lovable.app, un service de création de sites propulsé par IA.
📦 Distribution des charges malveillantes
Les URLs malveillantes identifiées se répartissent ainsi :
- 49,6% via Discord
- 23,4% via MediaFire
- 8,2% via GitHub
- 4,6% via Dropbox
Des téléchargements infectés ont également été hébergés sur Planet Minecraft et EndMods. La promotion s’effectue via Discord, Reddit et d’autres espaces communautaires.
📊 Impact mesuré
- McAfee WebAdvisor a bloqué plus de 6 300 tentatives d’accès aux sites malveillants sur le dernier mois
- Une investigation antérieure a lié WeedHack à plus de 116 464 joueurs infectés
- L’infrastructure C2 principale a été perturbée, mais le réseau de distribution reste actif
🧩 Type d’article
Publication de recherche / analyse de menace, basée sur un rapport McAfee partagé avec CyberSecurityNews, visant à documenter la campagne WeedHack et ses indicateurs de compromission.
🧠 TTPs et IOCs détectés
TTP
- T1608.006 — Stage Capabilities: SEO Poisoning (Resource Development)
- T1583.001 — Acquire Infrastructure: Domains (Resource Development)
- T1608.001 — Stage Capabilities: Upload Malware (Resource Development)
- T1204.002 — User Execution: Malicious File (Execution)
- T1036.005 — Masquerading: Match Legitimate Name or Location (Defense Evasion)
- T1105 — Ingress Tool Transfer (Command and Control)
IOC
- Domaines :
glazed-client.com— VT · URLhaus · ThreatFox - Domaines :
www.radium-client.com— VT · URLhaus · ThreatFox - Domaines :
seedcrackerx.github.io— VT · URLhaus · ThreatFox - Domaines :
xenonclient.com— VT · URLhaus · ThreatFox - Domaines :
xenoclient.lol— VT · URLhaus · ThreatFox - Domaines :
nova-client.com— VT · URLhaus · ThreatFox - Domaines :
cheatlib.xyz— VT · URLhaus · ThreatFox - Domaines :
meteorclients.com— VT · URLhaus · ThreatFox - Domaines :
22qq-client.com— VT · URLhaus · ThreatFox - Domaines :
kryptonclientcrack.lovable.app— VT · URLhaus · ThreatFox - Domaines :
endmods.com— VT · URLhaus · ThreatFox - URLs :
https://glazed-client.com/— URLhaus - URLs :
https://github.com/Hl3n/GambleRigMod— URLhaus - URLs :
https://www.radium-client.com/— URLhaus - URLs :
https://discord.com/channels/1467145812906872834/— URLhaus - URLs :
https://seedcrackerx.github.io/— URLhaus - URLs :
https://github.com/seedcrackerx/seedcrackerx.github.io— URLhaus - URLs :
https://xenonclient.com/— URLhaus - URLs :
https://xenoclient.lol— URLhaus - URLs :
https://nova-client.com/— URLhaus - URLs :
https://cheatlib.xyz/— URLhaus - URLs :
https://discord.com/channels/1478170973755936990— URLhaus - URLs :
https://meteorclients.com— URLhaus - URLs :
http://22qq-client.com/— URLhaus - URLs :
https://kryptonclientcrack.lovable.app— URLhaus - URLs :
https://github.com/lsellh/— URLhaus - URLs :
https://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar— URLhaus - URLs :
https://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jar— URLhaus - URLs :
https://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip— URLhaus - Fichiers :
mousetweaks-fabric-mc1-21-9-2-29.jar - Fichiers :
no-delay-optimizer1-21-4.jar - Fichiers :
KRYPTON-CLIENT1.0.zip
⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 25 août 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.
Malware / Outils
- WeedHack (loader)
🟢 Indice de vérification factuelle : 78/100 (haute)
- ✅ cryptika.com — source reconnue (Rösti community) (20pts)
- ✅ 7459 chars — texte complet (fulltext extrait) (15pts)
- ✅ 32 IOCs (IPs/domaines/CVEs) (10pts)
- ✅ 1/6 IOC(s) confirmé(s) (ThreatFox, URLhaus, VirusTotal) (8pts)
- ✅ 6 TTPs MITRE identifiées (15pts)
- ✅ date extraite du HTML source (10pts)
- ⬜ aucun acteur de menace nommé (0pts)
- ⬜ pas de CVE à vérifier (0pts)
IOCs confirmés externellement :
glazed-client.com(domain) → VT (14/91 détections)
🔗 Source originale : https://www.cryptika.com/top-google-results-for-minecraft-client-led-gamers-to-malware-mcafee-finds/