🎯 Contexte

Source : Cryptika (relayant CyberSecurityNews), publié le 25 août 2026. McAfee a publié un rapport détaillant la campagne WeedHack, une opération de distribution de malware ciblant les joueurs Minecraft via l’empoisonnement de résultats de recherche Google (SEO poisoning).

🔍 Mécanisme d’attaque

Les attaquants clonent des sites officiels de clients Minecraft populaires (Xenon Client, Glazed Client, Radium Client, Nova Client, Meteor Client, SeedCrackerX, 22qq-client, Krypton Client) en reproduisant fidèlement :

  • Les pages de téléchargement et d’installation
  • Les FAQ et crédits
  • Les liens vers les dépôts GitHub légitimes

Les faux sites sont positionnés en tête des résultats Google, notamment les deux premiers résultats pour la recherche « Xenon Client ». Un site malveillant a même été construit via lovable.app, un service de création de sites propulsé par IA.

📦 Distribution des charges malveillantes

Les URLs malveillantes identifiées se répartissent ainsi :

  • 49,6% via Discord
  • 23,4% via MediaFire
  • 8,2% via GitHub
  • 4,6% via Dropbox

Des téléchargements infectés ont également été hébergés sur Planet Minecraft et EndMods. La promotion s’effectue via Discord, Reddit et d’autres espaces communautaires.

📊 Impact mesuré

  • McAfee WebAdvisor a bloqué plus de 6 300 tentatives d’accès aux sites malveillants sur le dernier mois
  • Une investigation antérieure a lié WeedHack à plus de 116 464 joueurs infectés
  • L’infrastructure C2 principale a été perturbée, mais le réseau de distribution reste actif

🧩 Type d’article

Publication de recherche / analyse de menace, basée sur un rapport McAfee partagé avec CyberSecurityNews, visant à documenter la campagne WeedHack et ses indicateurs de compromission.

🧠 TTPs et IOCs détectés

TTP

  • T1608.006 — Stage Capabilities: SEO Poisoning (Resource Development)
  • T1583.001 — Acquire Infrastructure: Domains (Resource Development)
  • T1608.001 — Stage Capabilities: Upload Malware (Resource Development)
  • T1204.002 — User Execution: Malicious File (Execution)
  • T1036.005 — Masquerading: Match Legitimate Name or Location (Defense Evasion)
  • T1105 — Ingress Tool Transfer (Command and Control)

IOC

  • Domaines : glazed-client.comVT · URLhaus · ThreatFox
  • Domaines : www.radium-client.comVT · URLhaus · ThreatFox
  • Domaines : seedcrackerx.github.ioVT · URLhaus · ThreatFox
  • Domaines : xenonclient.comVT · URLhaus · ThreatFox
  • Domaines : xenoclient.lolVT · URLhaus · ThreatFox
  • Domaines : nova-client.comVT · URLhaus · ThreatFox
  • Domaines : cheatlib.xyzVT · URLhaus · ThreatFox
  • Domaines : meteorclients.comVT · URLhaus · ThreatFox
  • Domaines : 22qq-client.comVT · URLhaus · ThreatFox
  • Domaines : kryptonclientcrack.lovable.appVT · URLhaus · ThreatFox
  • Domaines : endmods.comVT · URLhaus · ThreatFox
  • URLs : https://glazed-client.com/URLhaus
  • URLs : https://github.com/Hl3n/GambleRigModURLhaus
  • URLs : https://www.radium-client.com/URLhaus
  • URLs : https://discord.com/channels/1467145812906872834/URLhaus
  • URLs : https://seedcrackerx.github.io/URLhaus
  • URLs : https://github.com/seedcrackerx/seedcrackerx.github.ioURLhaus
  • URLs : https://xenonclient.com/URLhaus
  • URLs : https://xenoclient.lolURLhaus
  • URLs : https://nova-client.com/URLhaus
  • URLs : https://cheatlib.xyz/URLhaus
  • URLs : https://discord.com/channels/1478170973755936990URLhaus
  • URLs : https://meteorclients.comURLhaus
  • URLs : http://22qq-client.com/URLhaus
  • URLs : https://kryptonclientcrack.lovable.appURLhaus
  • URLs : https://github.com/lsellh/URLhaus
  • URLs : https://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jarURLhaus
  • URLs : https://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jarURLhaus
  • URLs : https://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zipURLhaus
  • Fichiers : mousetweaks-fabric-mc1-21-9-2-29.jar
  • Fichiers : no-delay-optimizer1-21-4.jar
  • Fichiers : KRYPTON-CLIENT1.0.zip

⚠️ À propos de ces IOC — ils sont extraits automatiquement de l’article original le 25 août 2026 et n’ont pas fait l’objet d’une vérification externe. Un indicateur peut avoir été réattribué depuis : une IP de C2 peut redevenir un service légitime, un domaine sinkholé peut changer de propriétaire. Aucune garantie d’exactitude ni d’actualité — contrôlez leur validité avant tout usage opérationnel, en particulier avant de les injecter dans une blocklist ou un SIEM.

Malware / Outils

  • WeedHack (loader)

🟢 Indice de vérification factuelle : 78/100 (haute)

  • ✅ cryptika.com — source reconnue (Rösti community) (20pts)
  • ✅ 7459 chars — texte complet (fulltext extrait) (15pts)
  • ✅ 32 IOCs (IPs/domaines/CVEs) (10pts)
  • ✅ 1/6 IOC(s) confirmé(s) (ThreatFox, URLhaus, VirusTotal) (8pts)
  • ✅ 6 TTPs MITRE identifiées (15pts)
  • ✅ date extraite du HTML source (10pts)
  • ⬜ aucun acteur de menace nommé (0pts)
  • ⬜ pas de CVE à vérifier (0pts)

IOCs confirmés externellement :

  • glazed-client.com (domain) → VT (14/91 détections)

🔗 Source originale : https://www.cryptika.com/top-google-results-for-minecraft-client-led-gamers-to-malware-mcafee-finds/