Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Mojang Studios

Mojang Studios Vendor Cyber Rating & Cyber Score

Minecraft.net

Mojang Studios is a Microsoft-owned game studio based in Stockholm (Sweden) and Redmond (WA) with additional locations in London, Shanghai, and Tokyo as well as a partially remote workforce. We created Minecraft, the sandbox video game turned franchise that now includes two more games, novels, board games, apparel, and much more. We believe in the power of play and our mission is to build a better world through our work. At our studios, you’ll meet passionate and welcoming people with the same goal: to create games and products with a positive impact. Four core values guide everything we do: Fuel Passion. Minecraft encourages players to stay sharp and constantly evolve. We mirror that by bringing together enthusiastic people who are


Mojang Studios A.I CyberSecurity Scoring

Mojang Studios
Company Information
Website:http://Minecraft.net
Employees number:1,520
Number of followers:60,997
NAICS:51126
Industry Type:Computer Games
Homepage:Minecraft.net
Mojang Studios Risk Score (AI oriented)
Between 700 and 749
logo
Mojang StudiosComputer Games
Updated:
09/06/2026
727/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Mojang Studios Global Score (TPRM)
xxxx
logo
Mojang StudiosComputer Games
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Mojang Studios
Mojang StudiosModerate
Current Score
727Ba (MODERATE)
01000
2 incidents
-18.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
727Before Incident
MAY 2026
726Before Incident
APRIL 2026
744Before Incident
Cyber Attack
01 Apr 2026Mojang Studios
Minecraft and Offshore LC: New xlabs_v1 Botnet Targets Minecraft Servers Through ADB-Exposed Android Devices

New xlabs_v1 Botnet Targets Minecraft Servers via Exposed Android ADB Ports

724After Incident
HIGH-20
MOJOFF1777912275
New xlabs_v1 Botnet Targets Minecraft Servers via Exposed Android ADB Ports A recently discovered botnet, xlabs_v1, is exploiting Android devices with exposed Android Debug Bridge (ADB) ports to launch DDoS-for-hire attacks against Minecraft game servers. Based on the Mirai malware, this operation allows paying customers to flood servers with traffic, disrupting gameplay. The botnet targets any internet-facing device running ADB on TCP port 5555, including Android TV boxes, smart TVs, routers, and IoT hardware with ADB enabled by default. Once compromised, the malware drops a binary into `/data/local/tmp/`, executes it, and recruits the device into a botnet fleet. A specialized RakNet flood variant is used to attack Minecraft servers, with the bot binary distributed over TCP port 25565, the default Minecraft server port. Security researchers at Hunt.io uncovered the operation in early April 2026 while monitoring bulletproof-hosting netblocks. An exposed directory on a Netherlands-based server (176.65.139[.]44) hosted by Offshore LC (AS214472) revealed the full toolkit, including ELF binaries, infection payloads, and proxy credentials. Analysis of an unstripped development build exposed the C2 domain (xlabslover[.]lol), the operator’s handle (Tadashi), and an authentication token embedded in every bot variant. The botnet’s infrastructure is confined to a single /24 netblock, housing the C2 server, staging host, and distribution nodes. A Monero cryptomining campaign using VLTRig was also detected on the same netblock, though its connection to xlabs_v1 remains unconfirmed. ### Infection & Evasion Tactics Once installed, the malware employs multiple stealth techniques: - Blocks SIGINT signals to prevent interruption. - Erases startup arguments to hide its origin. - Decrypts strings (ChaCha20) containing C2 details. - Masquerades as `/bin/bash` to evade process monitoring. - Daemonizes itself, closing I/O handles to run silently. - Kills competing malware, including a rival bot on TCP port 24936. - Opens a fallback listener (TCP 26721) if C2 communication fails. - Profiles bandwidth by testing upload speeds via Speedtest servers, allowing tiered pricing for DDoS customers. Defenders are tracking indicators of compromise, including outbound connections to xlabslover[.]lol (TCP 35342) and pool[.]hashvault[.]pro, as well as suspicious files in `/data/local/tmp/arm7`. The campaign highlights the risks of unsecured ADB ports on internet-facing devices.
INCIDENT DETAILS -
TYPE
DDoS-for-hire
MOTIVATION
Financial gain (DDoS-for-hire services)
IMPACT
Systems Affected: Android TV boxes, smart TVs, routers, IoT hardware, Minecraft game serversDowntime: Disrupted gameplayOperational Impact: DDoS attacks causing service disruption
DATA BREACH
Data Encryption: ChaCha20 (for string decryption)File Types Exposed: ELF binaries, infection payloads, proxy credentials
MARCH 2026
744Before Incident
FEBRUARY 2026
744Before Incident
JANUARY 2026
760Before Incident
Cyber Attack
01 Jan 2026Mojang Studios
Minecraft and Impact Client: Weedhack MaaS Targets Minecraft Players to Steal Credentials and Hijack Accounts

Weedhack MaaS Operation Targets Minecraft Players with Sophisticated Malware

743After Incident
CRITICAL-17
MOJIMP1780993515
Weedhack MaaS Operation Targets Minecraft Players with Sophisticated Malware Since at least January 2026, Weedhack a Malware-as-a-Service (MaaS) operation has been actively targeting Minecraft players with a low-cost, subscription-based toolkit designed for credential theft, cryptocurrency wallet extraction, and account hijacking. Marketed through SEO poisoning, YouTube promotions, and fake mod websites, the service lowers the barrier for novice threat actors, increasing risks for gaming communities, particularly younger users. The malware primarily spreads via trojanized Java Archive (JAR) files disguised as popular Minecraft clients and mods, including Meteor Client, Aristois, LiquidBounce, and Impact Client. Upon execution, it hides under javaw.exe, decrypts Ethereum JSON-RPC endpoints, and uses smart contracts to dynamically retrieve command-and-control (C2) servers, complicating takedown efforts. Researchers identified 32 distinct JSON-RPC endpoints, over 3,820 malicious JAR samples, and 240+ distribution URLs linked to the campaign. Weedhack employs multi-stage attacks, using JNIC obfuscation to evade reverse engineering. Initial reconnaissance gathers system metadata, installed software, and attempts to bypass Windows Defender. Subsequent payloads steal browser credentials, Discord tokens, Steam and Telegram logins, and Minecraft session data, enabling account takeovers without password disclosure. The service offers tiered subscriptions, with a free version supporting credential theft, wallet targeting, and screenshot capture. Premium tiers (starting at ~$5/month) add remote-access features like keylogging, screen sharing, file management, reverse shells, and webcam monitoring. A customer dashboard provides malware builders, tutorials, and leaderboards, gamifying infections reportedly amassing over 116,000 hits. Researchers found evidence of misuse for harassment and cyberbullying, including the sharing of webcam footage in criminal forums. Many customers appear to be teenagers or young adults, exacerbating risks in youth-centered gaming communities. The operation’s professional-looking distribution sites and decentralized infrastructure further amplify its reach. Defenders are advised to treat Java-based gaming software as high-risk vectors, as Weedhack’s obfuscation and blockchain-driven C2 evade traditional signature-based detection. Mitigation strategies include sandboxing mod files, enforcing least-privilege Java policies, and blocking known malicious domains and JSON-RPC endpoints.
INCIDENT DETAILS -
TYPE
Malware-as-a-Service (MaaS)
MOTIVATION
Credential theftCryptocurrency wallet extractionAccount hijackingHarassmentCyberbullying
IMPACT
Browser credentialsDiscord tokensSteam loginsTelegram loginsMinecraft session dataCryptocurrency wallet dataWindows systems with Java installedOperational Impact: Account takeovers, unauthorized access to sensitive dataBrand Reputation Impact: Increased risk for gaming communities, particularly younger usersIdentity Theft Risk: HighPayment Information Risk: High (cryptocurrency wallets)
DATA BREACH
Browser credentialsDiscord tokensSteam loginsTelegram loginsMinecraft session dataCryptocurrency wallet dataSensitivity Of Data: High (personally identifiable information, financial data)Data Exfiltration: YesData Encryption: Malware uses JNIC obfuscation to evade detectionJAR filesPersonally Identifiable Information: Yes (Discord tokens, Telegram logins, Minecraft session data)
DECEMBER 2025
760Before Incident
NOVEMBER 2025
760Before Incident
OCTOBER 2025
760Before Incident
SEPTEMBER 2025
760Before Incident
AUGUST 2025
760Before Incident
JULY 2025
760Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Mojang Studios ?
?
What was Mojang Studios's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Mojang Studios's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Mojang Studios's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Mojang Studios's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Mojang Studios's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Mojang Studios's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Mojang Studios's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Mojang Studios's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Mojang Studios's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Mojang Studios's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Mojang Studios's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Mojang Studios's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Mojang Studios ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Mojang Studios's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?