AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev's headphones
An old friend messages you about an incredible crypto opportunity they’ve been using, showing screenshots of impressive returns. The platform looks professional and the interface is slick, so you decide to invest a few thousand dollars to test it. Seeing your money grow daily encourages you to add more. Just when you want to withdraw your funds, the platform vanishes overnight, your friend stops responding, and you realize the entire thing was an elaborate hoax designed to separate you from your savings.
Incidents like these don’t only target tech enthusiasts or risk-seeking traders. The victims also included retirees, first-time investors, and everyday people trying to build financial security who are systematically targeted by criminal operations.
If you are considering investing in cryptocurrency, this guide will help you learn about common types of crypto fraud, recognize their warning signs, and adopt strategies to avoid falling victim to crypto-related cyber threats.
Crypto and NFT scams are fraudulent schemes that exploit the unique characteristics of blockchain-based digital assets to deceive victims and steal their money or tokens. Unlike traditional financial fraud, these scams leverage the irreversible and complex nature of blockchain transactions, the lack of consumer protection mechanisms in an unregulated sector, and the fear of missing out on the next big opportunity.
Cryptocurrency is digital money that uses cryptography for security and is traded on decentralized networks called blockchains. It is digital cash that no single bank or government regulates. On the other hand, non-fungible tokens (NFTs) are unique digital certificates of ownership recorded on a blockchain, commonly used to represent digital art, collectibles, or membership rights. Being non-fungible means each token is one-of-a-kind and can’t be exchanged one-to-one like currency.
The scams targeting these assets take many forms, including fake investment platforms that display fabricated profits, fraudulent token projects where creators disappear with investors’ money, phishing websites that steal your digital wallet credentials, and long-con relationship scams. Unfortunately, transactions related to these scams cannot be reversed by calling your bank or credit card company. Once your crypto or NFTs are gone, they’re almost always gone for good.
In 2024, the Federal Bureau of Investigation’s Internet Crime Complaint Center recorded 859,000+ cybercrime complaints, with total losses of $16.6 billion, a 33% increase over 2023. Of that total, approximately $9.3 billion involved crypto investments or payments, spread across roughly 150,000 complaints.
Losses from global rug-pull scams, which are phony crypto offerings that quickly skyrocket and then plunge to near worthlessness, reached nearly $6 billion in early 2025, despite a decline in incidents.
Scammers now prefer cryptocurrency as the payment method for all kinds of fraud, whether it’s for tech support, romance, phishing, or extortion scams, because it’s difficult to trace and impossible to reverse. The moment someone tells you to download a crypto wallet app or send payment via Bitcoin, Ethereum, or any other digital currency, you’re likely dealing with a criminal.
Because of the decentralized, borderless nature of cryptocurrency, international criminal syndicates are able to operate from jurisdictions with weak enforcement while targeting victims worldwide. This problem isn’t just affecting young, tech-savvy early adopters or risk-seeking day traders. It is also affecting ordinary people worldwide, including first-time investors and victims of other types of scams across all age groups.
Individuals aged 60 and over, who lost a total of $2.8 billion in 33,000 crypto fraud incidents in 2024, face particularly severe financial impact as this amount represents their life savings, retirement funds, or money earmarked for healthcare, housing, or supporting family members. The emotional and financial devastation extends far beyond the dollar figures.
Older adults are so heavily targeted because they’re more likely to have substantial savings available to invest, may be less familiar with how cryptocurrency works, and often have more time to engage with scammers. In some cases, individuals were seeking to financially recover after recent market downturns, making high-return crypto promises particularly appealing.
Younger investors are targeted through different channels, such as social media, but the fundamental vulnerability remains the same: the promise of quick wealth and sophisticated social engineering.
Considered the most devastating category, pig-butchering scams originate from the farming practice of fattening a pig before slaughter, chillingly describing the scammer’s approach. These long cons run for months as criminals build relationships with victims through dating apps, social media, or wrong-number texts that turn into friendly conversations.
Gradually, the scammer will introduce the topic of cryptocurrency, positioning themselves as either a successful investor or someone learning from a knowledgeable mentor. Patiently, they guide the victim onto a fake but professionally designed, fully functional trading platform that shows real-time market data and walk them through making initial deposits and trades. On screen, the victim sees their account balance grow, which encourages them to deposit increasingly larger sums. Many even liquidate retirement accounts, take out loans, or sell property to invest more.
When the victim attempts to withdraw funds, the platform suddenly requires tax payments or verification fees, or threatens frozen accounts unless more money is deposited.
If victims refuse to send additional funds, the scammer ghosts them, the platform shuts down, and they discover that no trading ever occurred. Every dollar they sent went directly into criminal wallets.
Modern rug pull schemes are named for the action of pulling the rug out from under someone and leaving them shocked or helpless. One popular rug-pull method involves memecoins such as Dogecoin and Shiba Inu, which were hype-driven cryptocurrencies inspired by internet trends. Another involves DeFi (decentralized finance) projects, which offer financial services such as trading, lending, and investing outside of traditional banks.
Both can be legitimate, but their fast-moving, lightly regulated nature also makes them prime targets for scams, especially rug pulls where creators suddenly drain funds and disappear. However, these schemes do not offer a clear utility or roadmap, relying entirely on hype, memes, and community without articulating a specific use case, technical innovation, or development path.
To build credibility before they exit, scammers might:
Targeting NFT holders and crypto traders, this evolving scam includes:
The common thread across all these attacks is social engineering combined with the irreversible nature of blockchain transactions. Your confusion, an urgent email, one click, and your assets are gone with no way to reverse the transaction.
From 2020 to 2022, many of these early crypto and NFT scams consisted of poorly designed websites, unrealistic promises, and little effort to hide criminal intentions. Today, crypto criminals have become more efficient and effective. As an example, the number of rug-pull incidents declined by about 66% in early 2025, yet the total value stolen still exploded to $6 billion, up from roughly $90 million the year before.
Organized crypto scam operations are characterized by:
Protecting yourself from modern crypto scams requires more than awareness; it demands consistent habits, smart decision-making, and the right tools. As threats continue to evolve, building strong security practices today is the best way to stay ahead of increasingly sophisticated attacks.
Given that investment fraud is now the top fraud category by value in the U.S. and crypto-enabled fraud accounts for the majority of those losses, you will need to critically evaluate whether investing in cryptocurrency or NFTs aligns with your financial goals and risk tolerance.
This space combines extreme price volatility, complex technical requirements, irreversible transactions, minimal consumer protection, and a target-rich environment for criminals. If any of the following apply to you, your wisest choice is to proceed with extreme caution or avoid crypto investment entirely:
Choosing not to invest in crypto isn’t missing out, but making a risk-aware decision. Traditional, regulated investment vehicles may offer lower potential returns, but they come with legal protections, regulatory oversight, and mechanisms for recovering from fraud.
If you decide to invest in cryptocurrency or NFTs anyway, adopt these fundamental security practices to dramatically reduce your vulnerability:
If someone reaches out to you through any medium who steers the conversation to cryptocurrency investment opportunities, you’re almost certainly being targeted for fraud. Legitimate investment opportunities don’t find you this way.
Similarly, any communication that promises guaranteed returns, uses urgency, or pressures you before you can independently verify information is a red flag.
Before depositing funds anywhere, verify the platform’s legitimacy through multiple independent sources. Look for:
If you’re holding cryptocurrency or NFTs yourself rather than on an exchange, you’re personally responsible for security. Essential practices include:
Discovering you’ve been scammed is devastating, but taking immediate action could limit the damage and help law enforcement track and stop criminal operations:
Scammers often follow successful scams with additional pitches: recovery services usually run by the same criminals, tax payments supposedly required to unlock frozen funds, or claims that you’re so close to breaking even if you just invest a bit more. Every additional dollar you send is stolen money. Stop entirely.
Before anything disappears or times out, make sure to save:
This documentation is essential for law enforcement investigations and any potential recovery efforts.
While full recovery is rare, rapid reporting has occasionally allowed exchanges to freeze funds or helped international task forces seize assets before they’re fully laundered. Don’t expect miracles, but don’t assume recovery is impossible either.
Make formal reports to the:
If you’ve lost large sums, consider consulting with lawyers who specialize in cryptocurrency fraud or employing blockchain forensics firms that can trace funds across chains.
After a crypto scam, many victims are approached by fake recovery specialists who claim they can get your money back for an upfront fee in, you guessed it, cryptocurrency. These are almost always the same criminals or their associates running a second scam. Legitimate legal professionals work on contingency or retainer, and will not ask victims to send cryptocurrency for recovery services.
Comprehensive cybersecurity solutions may not be a guaranteed shield against all fraud, but they serve as a critical layer that catches threats you might not spot in that moment. Solutions such as McAfee+ help block known phishing sites and warn you before you enter credentials or connect wallets to fraudulent platforms. They also help detect malware and keyloggers that capture your password and seed phrase keystrokes, take screenshots when you open wallet applications, or even replace destination addresses in your clipboard when you copy-paste. Antivirus and anti-malware tools continuously monitor for threats and help remove them before they can compromise your security.
A secure virtual private network (VPN) can protect your connection on public Wi-Fi networks or compromised routers, preventing man-in-the-middle attacks that might intercept your login credentials or transaction data.
Since many crypto scams begin with or lead to broader identity theft, identity monitoring services can alert you if your personal information, passwords, or financial details appear in data breaches or on dark web marketplaces. This early warning allows you to change compromised credentials before they’re exploited.
The rising number of crypto-related fraud incidents and losses represents a grim milestone. As long as these scams promise high returns and operate with minimal oversight, criminal organizations will continue developing new tactics to steal from investors.
Going forward, your effective defense strategy will combine healthy skepticism, technical hygiene, continuous education, and practical tools. Approach any crypto investment opportunity with a questioning eye until you’ve independently verified that it is legitimate.
Maintain strong security practices, including using hardware wallets for significant holdings, storing seed phrases offline, enabling two-factor authentication everywhere, and carefully verifying transactions before approving.
Most importantly, build a network of trusted advisors, such as family members, friends, or financial professionals, who can offer guidance when you’re evaluating opportunities. Share what you’ve learned from this article and other McAfee guides with people in your life who might be exploring crypto investments, especially those who may be more vulnerable to relationship-based scams.
The post How to Spot a Crypto Scam: The Top Red Flags to Watch For appeared first on McAfee Blog.
A data breach doesn’t have to hit the company you shopped with directly to put your information at risk.
That’s the lesson from this week’s Pokémon Center breach. Customers in the United Kingdom and Germany are being notified that personal and order information was exposed after attackers compromised CEVA Logistics, the third-party company used to fulfill and ship Pokémon Center orders.
The good news: Pokémon Center says CEVA did not have access to customers’ payment-card information.
The bigger concern is what criminals could potentially do with the information that was exposed, particularly when it can make a phishing message look unusually convincing.
According to breach notifications reviewed by BleepingComputer, attackers may have obtained Pokémon Center customers’ full names, mailing addresses, phone numbers, email addresses, and information about the products they ordered. The affected customers were in the UK and Germany.
The intrusion occurred at CEVA Logistics rather than Pokémon Center itself. Reporting indicates attackers accessed CEVA systems between late July and August 1, disrupting operations at eight European warehouses and affecting multiple retailers. Valve previously notified European Steam hardware customers that their information had also been exposed through the CEVA incident.
A name and email address may not seem as sensitive as a credit-card number. But when criminals also know your address, phone number, and what you recently bought, they have something valuable: context.
Context helps scammers make phishing messages believable.
Phishing is when a criminal pretends to be a trusted company or person to persuade you to click a malicious link, hand over a password, share personal information, or send money.
After a breach like this, criminals could potentially impersonate Pokémon Center, a delivery company, or another retailer and reference details that make their message feel legitimate.
They might claim an order needs to be rescheduled, a delivery fee must be paid, or a refund is waiting. Knowing that you really placed an order can make the bait much harder to spot.
Importantly, there is currently no evidence that the stolen Pokémon Center information is being used in such a campaign. But personalized phishing is a common reason breached contact and transaction information deserves attention.
Pokémon Center says the breach occurred at its logistics provider, CEVA, not its own shopping platform.
Names, addresses, phone numbers, email addresses, and order details may have been exposed.
Pokémon Center says payment-card information was not available to CEVA.
Real order details could make future phishing or delivery scams appear more credible.
Customers should independently verify unexpected messages about refunds, cancellations, or deliveries.
Getting a breach notification doesn’t necessarily mean someone has already misused your information. It does mean you should take a few steps to make that information harder to use against you.
1) Find out exactly what was exposed. Read the company’s breach notice carefully. An exposed email address calls for different precautions than a stolen password, Social Security number, financial information, or medical record.
2) Secure the accounts that could be at risk. Change any exposed or reused passwords, use a unique password for every account, and turn on multi-factor authentication where it’s available. If sensitive financial or identity information was stolen, consider a credit freeze or fraud alert as well.
3) Be extra skeptical of messages that know something about you. Breached information can help scammers create convincing emails, texts, and calls. A message that knows your name, address, recent purchase, or other real details isn’t necessarily legitimate. Go directly to the company’s website or app to verify unexpected requests rather than clicking a link or calling a number in the message.
Before a breach
Personal Data Cleanup reduces your digital footprint by removing your personal information from many data broker sites, making it harder for scammers to find and target you.
Online Account Cleanup scans for accounts you no longer use and helps you delete them, along with your personal info.
During a breach
Identity Monitoring watches for your personal information, including email addresses, driver’s license numbers, passport numbers, bank accounts, credit cards, Social Security numbers, phone numbers, and more, across the dark web and known data leaks.
Plus, we alert users on average up to 10 months earlier than similar services, so you can act fast when your personal information appears where it shouldn’t.
After a breach
Scam Detector identifies suspicious texts, emails, and links that often follow major breaches, while web protection blocks malicious websites designed to steal even more of your information.
FBI warns about callers impersonating federal agents. The FBI’s Boston Division is warning about scammers who spoof its real phone number, pretend victims are connected to crimes, and then try to move conversations onto encrypted messaging apps. The key reminder: caller ID can be faked, and the FBI says it will not call private citizens to demand payment, threaten arrest, or request sensitive information.
CareCloud breach grows to more than 3.75 million patients. Healthcare technology company CareCloud has confirmed with federal regulators that hackers stole personal and medical information belonging to more than 3.75 million people, including Social Security numbers, health information, government-issued ID numbers, and some financial data. Because medical and identity information cannot simply be replaced like a password, affected people should take breach notifications particularly seriously.
Hacker claims millions of corporate directory records were stolen. A cybercriminal known as “TheHatman” is offering databases allegedly taken from the Microsoft Azure and Entra environments of several major companies, although some named organizations dispute that their current systems were breached and say portions of the information appear old. Even older employee information can still be useful for impersonation and targeted phishing, so the claims are worth watching without treating every advertised dataset as independently confirmed.
✓ Treat unexpected delivery messages with caution. Open the retailer or carrier’s official app or website instead of following a link in a text or email.
✓ Don’t trust caller ID alone. Scammers can spoof a legitimate organization’s real phone number.
✓ Use unique passwords and multi-factor authentication. Stolen personal information becomes more dangerous when criminals can also get into your accounts.
✓ Pay attention to breach notices. Knowing exactly what information was exposed helps you recognize the scams criminals may try next.
And we’ll be back next week with more cybersecurity news and scam alerts.
The post Pokémon Center Breach Shows Why Your Delivery Data Matters: This Week in Scams appeared first on McAfee Blog.
Authored by Aayush Tyagi
McAfee Labs’ latest investigation into the WeedHack malware campaign found that the threat has continued to evolve even after its original command-and-control infrastructure was disrupted by McAfee. Researchers identified multiple active websites still distributing WeedHack to gamers, often by impersonating legitimate Minecraft clients, offering paid tools for free, or using trusted platforms to make malicious downloads appear credible.
Among the findings:
→ More than 6,300 attempts to access malicious sites were blocked by McAfee WebAdvisor in the past month.
→ Researchers found lookalike gaming websites designed to closely replicate legitimate projects, including their branding, feature lists, FAQs, installation guides, developer credits, and links to genuine GitHub repositories.
→ In one case, the top two Google results observed by researchers for a popular Minecraft client led to sites distributing WeedHack, demonstrating how SEO poisoning can put malicious downloads directly in gamers’ paths.
→ Nearly half of the malicious URLs identified were Discord links (49.6%), followed by MediaFire (23.4%) and GitHub (8.2%), showing how attackers can use familiar platforms alongside fake websites to distribute malware.
→ Researchers also identified a malicious site built using an AI-powered website creation platform, illustrating how readily available tools can make it easier to launch convincing new malicious sites.
Threats like these show why protection needs to start before a malicious download ever reaches your device. McAfee helps block dangerous websites and downloads before malware has a chance to install, helping you stay focused on the game.
Threats like these show why protection needs to start before a malicious download ever reaches your device. McAfee helps block dangerous websites and downloads before malware has a chance to install, helping you stay focused on the game.
2026 has seen a significant shift in malware tactics, where traditional perimeter breaching techniques are being traded in for more elusive methods, such as AI-powered phishing and widespread deployment of Info-stealer malware. Over 560,000 new malware variants are detected every day, with infostealers accounting for the most active category.
McAfee Labs has also seen a significant spike in Malware-as-a-service (MaaS) campaigns, that offer their customers access to sophisticated infostealers and backdoor malware samples at minimal cost. These campaigns provide detailed tutorials to their customers, teaching them how to target popular gaming software, develop authentic-looking websites, and implement SEO Poisoning techniques in order to bamboozle gamers and infect their systems.
Recently, McAfee Labs has covered a Malware-as-a-service campaign, called ‘Weedhack’ that infected over 116,464 gamers and utilized SEO Poisoning techniques to infect such a large user base.
Read the original article here: Game Over: WeedHack – The Rise of Minecraft Malware-as-a-Service Campaigns
While uncovering the depths of this campaign, we’ve encountered multiple websites and file hosting services that are still active and distributing WeedHack malware. In this article, we cover some of the most prominent examples we’ve encountered in the wild to educate our readers and provide key insights on how to identify and avoid such malicious websites.
Note: This list is not exhaustive, and there may be additional websites that are not covered in this article.
During our investigation of this campaign, we observed that most of these websites appear legitimate, as they are well-crafted and often mimic legitimate websites. We observed a series of dedicated brand-impersonation attacks targeting several popular Minecraft clients.
We published the original article in the first week of July, and, as a result, we’ve seen a disruption in WeedHack’s campaign: its C2 server is no longer active. Consequently, we have observed a shift in tactics by these attackers.
The WeedHack Dashboard has been taken down, yet we’ve discovered websites that are actively spreading WeedHack malware.
Out of these URLs, most belonged to file-hosting services:
The remaining URLs were customer-facing websites designed to deceive users.
In the last month, McAfee WebAdvisor has prevented more than 6,300 users from accessing these malicious websites. At the time of writing this blog, the following websites were still distributing WeedHack malware.

This website ‘glazed-client.com’ replicates the original website called ‘glazedclient.com’. It provides a free and open-source Minecraft add-on called ‘Glazed Client’ designed specifically for DonutSMP server.
The website contains a feature list, along with Archive, Credits, and FAQ sections, that are identical to those on the original website.

Under the download section, the website provides three download options, and all of them are infected with WeedHack.

This website has a GitHub link, which links to a legitimate GitHub repository in order to build trust with the visitors.

The website ‘radium-client.com’ is replicating a legitimate website called ‘radiumclient.com’. The original website offers Minecraft client for $9.99 per month, but the malicious website offers the same tool for free.
The malicious replica also has a detailed feature and download section. The downloaded JAR file is infected with WeedHack.

In this instance, the malicious website contains a discord link, similar to the original website, but it points to a channel called ‘EasyClients’, that has over 1,900 members.

This channel offers 7 different DonutSMP clients for free (Image 7, Highlighted in Red) which are also infected with WeedHack.


In this example, we see GitHub’s web hosting service ‘GitHub.io’ being exploited by attackers. Here they are impersonating ‘SeedCrackerX’ tool, which is a Minecraft seed cracking software capable of identifying the exact world seed used to generate a Minecraft world.

Here, the malicious websites imitate the original website ‘seedcrackerx.com’, by replicating its fonts and color palette. The website also includes an elaborate tutorial and FAQ section, educating the visitors on how to properly install the tool.

Under the download section, the website offers seven versions to choose from, but all of them are infected with WeedHack. (Highlighted in Red)
This malicious website has also linked the genuine GitHub repository hosting the SeedCrackerX tool (Highlighted in Green), to appear more legitimate.
Xenon Client is one of the most popular Minecraft Clients, known for being lightweight, community driven and offering niche vanilla-friendly utilities. Given its widespread popularity, this client is a prominent target for threat actors.

During our research, we identified that the top two Google search results for ‘Xenon Client’ directed users to websites (Highlighted in Red) that are spreading WeedHack.

The “xenoclient.lol” website is particularly noteworthy, for the range of features and support it offers. The website includes comprehensive download and installation guides, as well as FAQ and Credits sections. Additionally, it lists the original Xenon Client GitHub repository and features a community section for like-minded gamers, further enhancing its professional appearance.

It offers 2 purchase options for free and premium, where the premium version is listed for $5.

The free option, on the other hand, offers six download options for the main client and six additional options for the client optimizer. At the time of writing, only one download link remains operational (highlighted in red), and it delivers a payload infected with WeedHack.
Another website, “xenonclient.com,” is also targeting Minecraft players, luring them with a free version of the same client.

Similar to other websites in the campaign, this site includes an installation guide and a feature list for the Xenon Client to enhance its apparent legitimacy.

The final JAR file downloaded from this website infects users with WeedHack.
Nova client is an open-source client designed for Minecraft Bedrock Edition.

This client is an easy target for attackers because it lacks an official website. The legitimate client is hosted on GitHub and Modrinth; however, attackers have created a spoofed website and leveraged SEO poisoning techniques to outrank the official sources in search results.

This website also includes a Features page, installation guide, and FAQ section. In addition, it displays screenshots from the legitimate Nova Client to deceive users.
What is interesting here is that attackers have also included a credits section, which is common with legitimate Minecraft client websites. However, they do not mention anyone who has actually worked on the project and instead used generic team names.

The download section provides Nova Client for Minecraft 1.21.11, but the download file spreads WeedHack malware.

CheatLib advertises that their clients have been downloaded over 1.6 million times, are free from malware and offers round-the-clock support.

Similar to other such websites, it also features a setup guide and a FAQ section to address common user issues.

They provide eight Minecraft Mods and inform users which Minecraft servers and anti-cheat systems they can bypass, as well as the current status of each mod.

Although the website offers eight distinct mods, all eight files share the same hash and distribute the WeedHack payload.

This website also links to a Discord channel called ‘CheatLib’ with over 220 users, which also provides access to WeedHack infected mods.

This malicious domain ‘meteorclients.com’ is impersonating a legitimate website ‘meteorclient.com’. They claim that this client has been downloaded over 10 million times and has over 15 thousand active users at any given time.

The Team section contains the names of the legitimate Meteor Client developers, which appear to have been copied from the project’s official website, to create an appearance of authenticity.

They also provide an interactive preview of Meteor client on the website, enabling users to test and familiarize themselves with the client. The website offers a single download option, which is infected with WeedHack.
22qq-client is a Minecraft Mod for Crystal PVP servers.

This mod does not have a dedicated website, and attackers are exploiting this issue. This website is meant to serve as the official page for the client.

The attackers attempt to establish credibility by using screenshots from the legitimate client.

They also offer an interactive preview of the client to give users an overview of its functionality. This website provides multiple download buttons, but all of them download the same JAR file, which is infected with WeedHack.
Krypton Client is a paid Minecraft tool for DonutSMP server, hosted on ‘kryptonclient.org’. This malicious counterpart claims to offer a cracked version of the tool.

The attackers have used an AI-powered tool called ‘lovable.app’ that allows customers to build and launch functional web applications and websites, using natural language. Such tools make it easier for attackers to deploy new malicious domains on the fly.

The website claims that the tool has been downloaded more than five thousand times and has been thoroughly tested for safety. They offer a single download option, which is infected with WeedHack.
In the course of our investigation, we observed that multiple attackers were exploiting various file hosting services to spread malware.

Links to these websites are then distributed via different communication channels, such as Discord, Reddit and other online platforms.

We also observed that threat actors extended their targeting beyond Minecraft clients, compromising various popular and independent community websites within the Minecraft ecosystem.

At the time of this analysis, the following Planet Minecart links were spreading WeedHack malware.
hxxps://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar
hxxps://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jar
Similarly, we observed another community website, called EndMods was also targeted by WeedHack.

The following link is still active, at the time of publication, and is still spreading the WeedHack malware.
hxxps://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip
At McAfee Labs, we investigate threats across the digital landscape, and gamers are a frequent target. We’ve seen multiple malware-as-a-service campaigns similar to WeedHack use fake downloads, impersonated websites, malicious mods, and other lures to target gaming communities.
AI-powered tools can make it faster and easier for scammers to create convincing websites, imitate legitimate services, and launch new campaigns at scale. That makes it even more important to know what you’re downloading, and where it’s coming from.
Here are a few ways gamers can stay safer:
→ Stick to trusted sources. Download games, mods, clients, and other files from official developer websites or reputable mod platforms whenever possible. If you can’t verify the source, don’t download it.
→ Never turn off your security software for a download. Be suspicious of any mod, cheat, or client that tells you to disable your antivirus or other protections before installing it.
→ Scan files before opening them. Check downloaded mods, installers, and archives before running them — even if they came from a popular gaming community or website.
→ Be skeptical of offers that seem too good to be true. “Free” premium features, exclusive cheats, cracked software, or paid clients can be used as bait to convince gamers to download malware.
→ Check the URL before you download. Scammers can create lookalike domains and convincing copies of legitimate gaming sites. Small changes in a web address can be a sign you’re on an impersonation site.
→ Pay attention to security warnings. If your antivirus flags a download, don’t automatically assume it’s a false positive. Stop and investigate before allowing the file to run.
→ Keep your devices and software updated. Install updates for your operating system, browser, games, and security software to help protect against known vulnerabilities.
| hxxps://glazed-client.com/ |
| hxxps://github.com/Hl3n/GambleRigMod |
| hxxps://www.radium-client.com/ |
| hxxps://discord.com/channels/1467145812906872834/ |
| hxxps://seedcrackerx.github.io/ |
| hxxps://github.com/seedcrackerx/seedcrackerx.github.io |
| hxxps://xenonclient.com/ |
| hxxps://xenoclient.lol |
| hxxps://nova-client.com/ |
| hxxps://cheatlib.xyz/ |
| hxxps://discord.com/channels/1478170973755936990 |
| hxxps://meteorclients.com |
| hxxp://22qq-client.com/ |
| hxxps://kryptonclientcrack.lovable.app |
| hxxps://github.com/lsellh/ |
| hxxps://static.planetminecraft.com/files/resource_media/mod/mousetweaks-fabric-mc1-21-9-2-29.jar |
| hxxps://static.planetminecraft.com/files/resource_media/mod/no-delay-optimizer1-21-4.jar |
| hxxps://endmods.com/wp-content/uploads/2026/02/KRYPTON-CLIENT1.0.zip |
The post WeedHack Returns: How SEO Poisoning is Leading Minecraft Fans to Malware appeared first on McAfee Blog.