Close Menu
NCIJ Network NCIJ Network
    What's Hot

    After killer quarter, Palantir CEO Alex Karp calls AI industry ‘Marxist’

    August 3, 2026

    Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

    August 3, 2026

    Strategy sells $395 million in Bitcoin and MSTR stock to buyback $81 million in STRC and build cash reserve to $4 billion

    August 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • After killer quarter, Palantir CEO Alex Karp calls AI industry ‘Marxist’
    • Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
    • Strategy sells $395 million in Bitcoin and MSTR stock to buyback $81 million in STRC and build cash reserve to $4 billion
    • Scientists reveal the hidden force driving the universe’s hottest fluid
    • Iran Denies Peace Talks With U.S. After Trump Walks Back Strikes
    • Trump’s Continued Claims of Vandalism at Reflecting Pool Disputed by U.S. Attorney Memo
    • Europe’s record-breaking heat sparks wildfires, drought in France, Greece and the UK
    • Rupert Lowe’s ‘olive branch’ to Farage piles more pressure on Reform leader | Restore Britain
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Fake Roblox Xeno script launcher pushes infostealer, RAT malware

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information.

    Xeno Executor is a popular Roblox utility for running scripts that players can use to automate actions or run custom code on the platform, including cheats.

    The tool isn’t an official part of the game, so the Roblox client periodically blocks existing versions, forcing the tool’s creators to release new  versions that run undetected.

    image

    Cybersecurity company Bitdefender discovered a campaign targeting Roblox users since the start of the year, rising sharply in March before stabilizing.

    The researchers found that the fake Xeno is promoted to Roblox players through gaming forums, Discord communities, or via compromised or impersonated accounts controlled by the threat actors.

    The attackers advertise the malware as an “undetected” version of Xeno, luring users looking for a version that wouldn’t be detected by Roblox’s anti-cheat protections.

    The victims download ZIP archives containing the fake Xeno installers along with instructions, or self-extracting archives that unpack content automatically.

    To make these packages look authentic, the attackers recreate the directory structure of a legitimate Xeno installation, include some genuine Lua scripts, and use plausible filenames.

    Once victims launch ‘xeno.exe,’ as instructed, believing it is the legitimate Xeno executable, they actually run the first-stage malware loader.

    The payload checks for a Java Runtime Environment, and extracts one if necessary, then reads a local file containing the validation keys for the attackers’ command-and-control (C2) server.

    It then launches an obfuscated Java payload disguised as ‘decompiler.exe,’ which performs environment checks, registers the victim, and downloads the final malware payload.

    Attack chain
    Attack chain
    Source: Bitdefender

    The final payload is a Java-based RAT and information stealer malware that combines credential theft with surveillance and remote administration capabilities.

    Its most important capabilities are summarized as follows:

    • Steals browser data including cookies and other stored user data from Chrome, Edge, Brave, Opera, and Vivaldi.
    • Targets online accounts and payment data, including Discord, Roblox, Minecraft, Microsoft Store tokens, and payment information associated with Discord and Microsoft Store accounts.
    • Steals cryptocurrency wallet data, with dedicated functionality targeting Exodus Wallet and support for identifying numerous other cryptocurrency wallets.
    • Provides surveillance capabilities, including keylogging, mouse activity logging, screenshot capturing, desktop streaming, and webcam access.
    • Enables full remote control, allowing attackers to upload and download files, execute PowerShell commands, and access an interactive remote shell.

    Bitdefender believes the campaign is the same as the one ThreatLocker previously documented as “Powercat,” but with significant updates to the malware’s capabilities and a new C2 infrastructure, indicating continuous evolution.

    Bitdefender has shared indicators of compromise (IoCs) for the campaign and recommends that Roblox players completely avoid installing third-party tools from obscure sources.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    Fake infostealer launcher Malware pushes RAT Roblox script Xeno
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

    EU ministers to back Spain as Ceuta crisis pushes migration up the agenda – POLITICO

    New DOUBLECUP ClickFix service hides malware in browser cache images

    Chinese Actor Weaponizes Deepseek AI Agent Against Security Firm

    Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    After killer quarter, Palantir CEO Alex Karp calls AI industry ‘Marxist’

    August 3, 2026

    Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

    August 3, 2026

    Strategy sells $395 million in Bitcoin and MSTR stock to buyback $81 million in STRC and build cash reserve to $4 billion

    August 3, 2026

    Scientists reveal the hidden force driving the universe’s hottest fluid

    August 3, 2026
    Latest Posts

    A Russian Spy, Suddenly Cast Into the Spotlight, Flees Japan

    July 23, 2026

    Did Trump accidentally declassify proof Russia tried to help him win 2020 election?

    July 23, 2026

    Trump Puts Section 338 Tariffs on Canada as Greer Foreshadows New Global Duties

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    After killer quarter, Palantir CEO Alex Karp calls AI industry ‘Marxist’

    August 3, 2026

    Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

    August 3, 2026

    Strategy sells $395 million in Bitcoin and MSTR stock to buyback $81 million in STRC and build cash reserve to $4 billion

    August 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.