Fake Minecraft Sites Are Still Spreading WeedHack After C2 Takedown

2026-08-25T08:51:37Z9d940886eb1dfbddd45a11357b88645333373052eea82249df86cb0c4d89b882
AI securityAndroid malwareIran-linked threat actorMinecraft-themed lureSEO poisoningToxicPandaWeedHackaccount takeoverbanking trojancredential theftcritical infrastructurecybercrimedata exfiltrationenergy sectoriAuthFlow v2infostealermalwarepasskey persistencephishingprivacyprompt injectionroad-camera securitywater infrastructure

What happened

Security Affairs feed covering active malware distribution campaigns, phishing and credential theft, Android banking malware, critical-infrastructure cyberattacks, vulnerable road cameras, and emerging AI security abuse. Notable threats include WeedHack infostealer propagation through fake Minecraft sites and SEO poisoning, iAuthFlow v2 phishing that enrolls attacker-controlled passkeys to persist beyond password resets, ToxicPanda 2.0 targeting financial applications across 16 countries, and reported Iran-linked attacks against energy and water infrastructure.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
9d940886eb1dfbddd45a11357b88645333373052eea82249df86cb0c4d89b882
Enrichment time
2026-08-25T08:51:37Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.