A malware campaign is targeting Roblox players with a fake version of the Xeno script executor, a tool commonly used to run custom Roblox scripts.
The malicious package is advertised as an “undetected” Xeno build. It is distributed through gaming forums, Discord communities, archives, and compromised accounts.
Researchers at Bitdefender said the campaign uses a multi-stage Java-based infection chain designed to appear to be a normal Xeno installation.
While victims believe they are installing a Roblox cheat, they instead deploy a powerful remote access trojan (RAT) and information stealer previously tracked as Powercat.
The threat is especially concerning because Roblox cheats often attract younger users.
An infected shared family computer could expose gaming accounts, Discord conversations, browser data, cryptocurrency wallets, payment information, webcam images, and personal documents.
Fake Xeno Delivers JavaRAT
The malicious archives imitate a legitimate Xeno folder structure and include copied Lua scripts to appear convincing. Some files use familiar names but contain junk data, while the supposed main program, xeno.exe, is actually the first-stage loader.
When launched, the fake executable checks for Java by looking for %LOCALAPPDATA%\Java\jre\bin\javaw.exe.

If Java is not available, it silently extracts a Java Runtime Environment from an embedded archive using a hidden PowerShell command.
The third-stage malware goes well beyond basic credential theft.
It can collect browser cookies and user data from Chrome, Edge, Brave, Opera, Opera GX, and Vivaldi. It also targets Discord, Roblox, Minecraft, Microsoft Store tokens, and several cryptocurrency wallets.
For Discord, the malware extracts browser-based tokens and can query account data, including saved payment methods.
It also collects Roblox cookies and searches for credentials or login information associated with Minecraft launchers, including Lunar, Feather, Prism, Modrinth, Meteor, and the official launcher.
The malware specifically targets Exodus cryptocurrency wallets. Researchers found code that can modify local Exodus application files, weaken security settings, capture wallet-related data, and send valid tokens back to the operators.
Its surveillance features make the campaign more dangerous than a typical gaming stealer.
Attackers can log keystrokes and mouse actions, capture screenshots, stream the victim’s desktop every 500 milliseconds, list connected displays, and access the webcam through Windows DirectShow components.
The RAT can also list, upload, download, rename, and replace files. It can execute Base64-encoded PowerShell commands and open an interactive shell, giving operators direct control of an infected machine.

It also supports payload updates, enabling attackers to remotely replace the malware with newer versions.
Bitdefender observed new C2 infrastructure and added functionality, indicating that Powercat remains under active development.
Researchers reported that infections began earlier in the year, rose sharply during the second half of March, and then continued at a steady rate.
Security teams should block the identified infrastructure, hunt for suspicious Java execution from %LOCALAPPDATA%, and review Run-key entries named Display Calibration.
Users should avoid unofficial cheats, executors, and “undetected” gaming tools, particularly those shared through Discord messages, forums, or untrusted archives.
Enabling multi-factor authentication and using updated endpoint protection can also limit account theft and post-compromise activity.
Indicators of Compromise
| IOC Type | Indicator | Description |
|---|---|---|
| MD5 | 4bdaf7792e908f163ebef137854c571d | Archive containing fake Xeno installation |
| MD5 | 9930036e8f787674db39094e21413e77 | Archive containing fake Xeno in |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.