A fake Roblox Xeno script launcher is infecting players with malware that steals sensitive information and provides remote access, according to cybersecurity company Bitdefender. Xeno Executor is a popular Roblox utility for running scripts that players can use to automate actions or run custom code on the platform, including cheats.
How the Malware Spreads
The fake Xeno is promoted to Roblox players through gaming forums, Discord communities, or via compromised or impersonated accounts controlled by the threat actors. The attackers advertise the malware as an 'undetected' version of Xeno, luring users looking for a version that wouldn't be detected by Roblox's anti-cheat protections.
The victims download ZIP archives containing the fake Xeno installers along with instructions, or self-extracting archives that unpack content automatically. To make these packages look authentic, the attackers recreate the directory structure of a legitimate Xeno installation, include some genuine Lua scripts, and use plausible filenames.
Malware Payload
Once victims launch ‘xeno.exe,’ as instructed, believing it is the legitimate Xeno executable, they actually run the first-stage malware loader. The payload checks for a Java Runtime Environment, and extracts one if necessary, then reads a local file containing the validation keys for the attackers' command-and-control (C2) server.
It then launches an obfuscated Java payload disguised as ‘decompiler.exe,’ which performs environment checks, registers the victim, and downloads the final malware payload. The final payload is a Java-based RAT and information stealer malware that combines credential theft with surveillance and remote administration capabilities.
Malware Capabilities
The malware's capabilities include stealing browser data, targeting online accounts and payment data, stealing cryptocurrency wallet data, and providing surveillance capabilities such as keylogging and webcam access. It also enables full remote control, allowing attackers to upload and download files, execute PowerShell commands, and access an interactive remote shell.
Bitdefender believes the campaign is the same as the one ThreatLocker previously documented as “Powercat,” but with significant updates to the malware’s capabilities and a new C2 infrastructure, indicating continuous evolution.
Bitdefender has shared indicators of compromise (IoCs) for the campaign and recommends that Roblox players completely avoid installing third-party tools from obscure sources. Security teams should test every layer before attackers do, as 54% of successful attacks are logged and only 14% are alerted on, according to a Picus whitepaper.
The whitepaper shows how breach and attack simulation tests SIEM and EDR rules so threats stop slipping by detection. Roblox players should be cautious when downloading and installing third-party tools, and should only use official sources to minimize the risk of infection.
- Steals browser data including cookies and other stored user data from Chrome, Edge, Brave, Opera, and Vivaldi.
- Targets online accounts and payment data, including Discord, Roblox, Minecraft, Microsoft Store tokens, and payment information associated with Discord and Microsoft Store accounts.
- Steals cryptocurrency wallet data, with dedicated functionality targeting Exodus Wallet and support for identifying numerous other cryptocurrency wallets.
- Provides surveillance capabilities, including keylogging, mouse activity logging, screenshot capturing, desktop streaming, and webcam access.
- Enables full remote control, allowing attackers to upload and download files, execute PowerShell commands, and access an interactive remote shell.
By being aware of these risks and taking steps to protect themselves, Roblox players can minimize the risk of infection and keep their personal data safe.
Source: BleepingComputer