WeedHack Malware: Detection and Removal Guide

Brendan Smith
Brendan Smith - Cybersecurity Analyst
5 Min Read
Editorial image showing a malicious Minecraft mod JAR trap for WeedHack malware.
WeedHack Minecraft malware campaign warning.

WeedHack is a Windows-focused, multi-stage Java Trojan distributed through fake Minecraft mods, clients, cheats, and utilities. Microsoft Defender detects related samples as Trojan:Java/WeedHack!MTB. If a suspicious JAR was only downloaded and never opened or loaded by Minecraft, remove it and scan the PC. If it ran or was loaded as a mod, treat the device and its accounts as exposed because WeedHack can steal sessions and passwords, change Defender exclusions, persist through scheduled tasks, and install remote-access components.

McAfee Labs reported more than 3,820 unique malicious JAR files and over 240 distribution URLs in the campaign. Its dashboard recorded 116,464 campaign hits as of the June 2026 report. That number describes dashboard and telemetry hits; it should not be read as a verified count of unique infected computers.

Who Is Affected

The main risk is to Windows users, parents, and Minecraft players who searched for clients, mods, cheats, FPS boosters, launchers, or utilities outside an official project page. WeedHack operators use YouTube videos, comments, and SEO-poisoned pages that imitate trusted mod sites. Some lures even place legitimate GitHub or Discord links beside the malicious download, which makes the clone look safer than it is.

Signal Risk and what to do
Unknown Minecraft JAR from a video, comment, mirror, or search-result clone Do not open it. Delete the download, empty the Recycle Bin, and run a full security scan.
The JAR ran directly or loaded through Minecraft Assume the malware may have reached later stages. Disconnect the PC, check persistence and Defender exclusions, then recover accounts from a clean device.
Discord, Steam, Microsoft, browser, Telegram, or wallet alerts Change the email password first, revoke sessions, enable MFA, and review recovery details and transactions.
Webcam threats, screen control, unexpected files, or remote commands Disconnect the PC immediately. Preserve messages as evidence, tell a trusted adult if a minor is involved, and plan a clean Windows reinstall.

Downloaded Versus Executed: Choose the Right Response

If the JAR was downloaded but never opened

A JAR sitting in Downloads is not the same as a JAR that executed. Do not double-click it or move it into the Minecraft mods folder to “test” it. Remove the file, scan the device, and verify the project through its long-lived official repository or developer page before downloading any replacement. Account rotation is usually unnecessary when you can confidently establish that the file never ran or loaded.

If the JAR ran or Minecraft loaded it

Use the full incident path. Disconnect the device from the network, scan for every stage, inspect security exclusions and scheduled tasks, and recover accounts from a separate clean device. Deleting the original mod is not enough: McAfee observed later stages that run from the user’s roaming profile and repeatedly restore components.

WeedHack Files and Persistence Clues

The following names and locations come from McAfee’s analyzed samples. They are diagnostic clues, not a universal list and not instructions to delete every similarly named Windows file.

  • DonutDupe.jar: an observed first-stage JAR that relaunches through javaw.exe, resolves the current command server, and loads the next stage in memory.
  • Elevator.jar: an observed second stage that uses cmstp.exe for elevation, drops WinDefConfig.cmd, and adds multiple Microsoft Defender path and process exclusions.
  • SecurityManager.jar: stored in an analyzed sample under %APPDATA%\Microsoft\SecurityUpdates\. It creates the JavaSecurityUpdater scheduled task to launch through javaw.exe at logon.
  • component.jar: the later remote-access stage. McAfee also observed a malicious RuntimeBroker.exe in %APPDATA%, not the legitimate Windows file in C:\Windows\System32.
  • JMonitoringTask: a watchdog task that runs the Java updater task every two minutes, allowing removed or disrupted components to return.
  • Telemetry lookalikes: an infostealer under %APPDATA%\Microsoft\Tlmtry and a misspelled WindowsRunetimeBroker.exe copy in the roaming profile were present in the analyzed chain.

A single matching name does not prove WeedHack by itself. Use the path, digital signature, creation time, parent process, Defender history, and the known suspicious JAR together. Never remove the legitimate C:\Windows\System32\RuntimeBroker.exe because a malware sample reused its name elsewhere.

How to Remove WeedHack Safely

  1. Disconnect the affected PC. Turn off Wi-Fi or unplug Ethernet. Do not sign in to important accounts from that device.
  2. Remove the lure without rerunning it. Delete the suspicious JAR, fake launcher, client, cheat, and matching copies in Downloads or the Minecraft mods folder. Do not download a community “remover” to the affected PC.
  3. Review Windows Security before scanning. Look for unexpected Microsoft Defender exclusions and check Task Scheduler for JavaSecurityUpdater, JMonitoringTask, or tasks launching scripts and JARs from the roaming profile. Record suspicious entries before removing them; do not change legitimate enterprise exclusions or unrelated tasks blindly.
  4. Update security definitions and run a full scan. Microsoft notes that Defender can detect and remove Trojan:Java/WeedHack!MTB, but remnant files and system changes can remain after the visible threat is quarantined.
  5. Use a second cleanup pass. Gridinsoft Anti-Malware can check for suspicious JAR stages, dropped executables, startup entries, scheduled tasks, hidden files, browser changes, and other persistence.
  6. Reboot and scan again. Recheck exclusions, scheduled tasks, and the suspicious roaming-profile paths. If components return, remote control occurred, security settings cannot be trusted, or the PC belongs to a child, back up personal documents only and reinstall Windows from clean installation media.

Quarantining the visible JAR may not undo an exclusion, watchdog task, remote-access component, or stolen browser session that was created after execution. A full persistence-aware scan is the practical next step when the file ran or the alert returns after reboot.

Scan for downloaded helpers and persistence.

Loaders, trainers, and game hack tools can fetch extra code after launch. Deleting the visible file may not remove helpers, scheduled tasks, Defender exclusions, or account-stealing components.

Scan for WeedHack leftovers

Recover Accounts From a Clean Device

  1. Secure the main email account first. Change its password, revoke unfamiliar sessions, verify recovery email and phone details, and enable MFA.
  2. Recover Microsoft and Minecraft access. Change the Microsoft account password, review recent sign-ins, revoke sessions where available, and remove unfamiliar security methods.
  3. Reset gaming and messaging sessions. Change Discord, Steam, and Telegram credentials and revoke active sessions or authorized apps you do not recognize.
  4. Replace browser-saved passwords. Prioritize accounts that were stored or used on the affected PC. A password change without session revocation may leave a stolen cookie usable.
  5. Protect cryptocurrency assets. If a wallet seed phrase or private key was stored in a browser, file, screenshot, or clipboard on the affected device, create a new wallet with a new seed on a clean device and move assets. Changing a wallet-app password does not replace an exposed seed.
  6. Watch for follow-on abuse. Check payment methods, marketplace accounts, recovery changes, new forwarding rules, and messages sent from compromised accounts.

For a broader sequence, use the infostealer after downloading a game or mod checklist. If Minecraft access was lost, follow the Microsoft account recovery after malware guide. Gridinsoft’s MaksStealer Minecraft mod cleanup explains another gamer-focused stealer pattern.

If a Child Is Threatened Through the Webcam

WeedHack’s paid remote-access features were used in harassment and cyberbullying, according to McAfee. A minor should not negotiate, pay, send more images, or follow the attacker’s instructions. Disconnect the affected device, cover or disable the camera, preserve screenshots and usernames without reopening suspicious files, and tell a parent, guardian, or another trusted adult immediately. Report the account to the platform and involve local law enforcement or a child-safety authority when there are threats, sexual extortion, stalking, or publication of private material.

Why Minecraft JAR Mods Need Source Verification

Minecraft: Java Edition has a large modding ecosystem, but a JAR is executable code. Players must evaluate the source and trust chain themselves. Prefer a developer’s established project page or long-lived repository, verify the exact domain independently, and reject any download page that tells you to disable antivirus protection or dismiss a security warning.

FAQ

What does Trojan:Java/WeedHack!MTB mean?

It is Microsoft’s detection name for a WeedHack-related Java Trojan. Microsoft says Defender detects and removes the threat, but a full scan and follow-up review are still important because files and system changes can remain.

Is every Minecraft mod dangerous?

No. The risk is highest with untrusted JARs, fake clients, and cloned mod pages. Use official project pages and established repositories, and avoid downloads promoted through video comments, ads, or newly created mirror sites.

Is deleting the Minecraft mod enough?

Only when you are confident it never executed or loaded. If the JAR ran, check Defender exclusions, scheduled tasks, roaming-profile artifacts, and accounts; then reboot and scan again.

Should I remove RuntimeBroker.exe?

Do not delete the legitimate Windows file in C:\Windows\System32. WeedHack samples used the same name from the user’s roaming profile. Treat path, signature, timing, and related tasks as the decision evidence.

References

  1. Aayush Tyagi, McAfee Labs. “Game Over: WeedHack – The Rise of Minecraft Malware-as-a-Service Campaigns.” McAfee Blog, June 2, 2026, accessed August 5, 2026. https://www.mcafee.com/blogs/other-blogs/mcafee-labs/weedhack-minecraft-malware-as-a-service-campaign-research/
  2. Microsoft Security Intelligence. “Trojan:Java/WeedHack!MTB Threat Description.” Microsoft, updated March 24, 2026, accessed August 5, 2026. https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Trojan%3AJava%2FWeedHack%21MTB
Share This Article
Cybersecurity Analyst
Follow:
Brendan Smith has spent over 15 years knee-deep in cybersecurity, chasing down malware from the gritty reverse-engineering of old-school trojans all the way to wrangling full-blown incident responses for small-to-medium businesses that couldn’t afford a full-blown breach. Over at Gridinsoft, he’s the guy piecing together those double-checked guides on nasty stuff like AsyncRAT ransomware—take last year, for instance, when his breakdowns caught more than 200 sneaky variants right in live scans, knocking user cleanup jobs down by a solid 40% and saving folks hours of headache.
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?