bleeping-computer · Crawled Aug 3, 2026

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

2 IoCs
Read original article ↗

AI Summary

A malicious campaign distributes fake Xeno Executor installers to Roblox players, delivering a Java-based information stealer and remote access trojan (RAT). The malware is promoted through gaming forums and Discord, masquerading as an 'undetected' version of the legitimate tool. Once executed, it deploys a multi-stage payload that steals browser data, credentials, cryptocurrency wallets, and enables surveillance and full remote control of the infected system. Bitdefender links this campaign to a previously documented threat known as Powercat, now with enhanced capabilities and updated C2 infrastructure.

AI-extracted · verify before operational use

Indicators of Compromise 2 extracted

Type Value Detail
Filename xeno.exe Details →
Filename decompiler.exe Details →