VYPR
researchPublished Aug 3, 2026· 1 source

Fake Roblox Xeno Script Launcher Delivers Infostealer and RAT Malware

Threat actors are distributing malicious installers disguised as the popular Roblox scripting tool Xeno Executor, infecting players with malware that steals credentials and provides remote access.

Cybersecurity researchers have uncovered a widespread campaign targeting Roblox players by distributing fake installers for the popular Xeno Executor scripting utility. These malicious installers, masquerading as legitimate versions of the tool, are designed to lure unsuspecting users into downloading and executing malware that can steal sensitive information and grant attackers remote control over compromised systems.

Xeno Executor is a third-party tool that allows Roblox players to run custom scripts within the game, often used for automation, cheating, or other modifications. Because it is not an official Roblox application, its functionality is frequently blocked by the game's anti-cheat measures, leading users to seek out "undetected" versions. Threat actors are exploiting this demand by advertising their malicious installers as the latest, undetectable versions of Xeno.

The campaign, identified by Bitdefender and observed to have sharply increased in March, involves threat actors promoting the fake Xeno installers through various online channels. These include gaming forums, Discord communities, and potentially compromised or impersonated social media accounts. The attackers meticulously recreate the appearance of legitimate Xeno installations, often packaging the malware within ZIP archives that contain fake executables and even genuine Lua scripts to enhance their credibility.

Upon execution of the disguised 'xeno.exe' file, victims unknowingly launch a multi-stage malware loader. This initial payload performs checks for a Java Runtime Environment, installing it if necessary, and then retrieves C2 server validation keys from a local file. Subsequently, it deploys an obfuscated Java-based component, disguised as 'decompiler.exe,' which further assesses the victim's environment, registers the compromised machine with the attackers, and proceeds to download the final, potent malware payload.

The ultimate payload is a sophisticated Java-based Remote Access Trojan (RAT) and information stealer. This malware is equipped with a wide array of malicious capabilities, including the theft of browser data such as cookies and stored credentials from popular browsers like Chrome, Edge, Brave, and Vivaldi. It also targets online account credentials and payment information for services like Discord, Roblox, Minecraft, and Microsoft Store, as well as cryptocurrency wallet data for Exodus Wallet and other common wallets.

Beyond credential theft, the malware offers extensive surveillance features. Attackers can leverage it for keylogging, monitoring mouse activity, capturing screenshots, streaming the victim's desktop, and even accessing the webcam. Furthermore, the RAT provides full remote control capabilities, allowing threat actors to upload and download files, execute arbitrary PowerShell commands, and establish an interactive remote shell on the compromised system.

Bitdefender notes that this campaign appears to be an evolved version of the "Powercat" operation previously documented by ThreatLocker, indicating continuous development and adaptation by the threat actors. The company has released indicators of compromise (IoCs) to aid in detection and mitigation efforts. Security experts strongly advise Roblox players to exercise extreme caution and avoid downloading any third-party tools or executables from untrusted or obscure online sources to prevent falling victim to such attacks.

Synthesized by Vypr AI