Attackers are distributing fake installers for the Xeno Roblox script executor through Discord communities, gaming forums, and compromised or impersonated accounts, luring players with claims of an "undetected" cheat tool. When victims run xeno.exe, the installer checks for Java, drops or installs a local Java runtime, retrieves validation data, and launches an obfuscated JAR masquerading as decompiler.exe, leading to a multi-stage infection chain tied to the previously documented Powercat malware family.
The final payload combines an infostealer with a remote access trojan, stealing browser cookies and saved data, Discord and Roblox tokens, Minecraft data, payment details, and cryptocurrency wallet information. It also supports keylogging, screenshots, webcam capture, desktop streaming, file transfer and manipulation, PowerShell execution, and interactive remote shell access, while using anti-analysis checks, persistence via the Windows Run registry key under "Display Calibration", and WebSocket-based command-and-control with self-update capability; researchers said the campaign has been active since the start of the year and poses particular risk to children and teenagers seeking Roblox cheats.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Bitdefender observed the campaign rising sharply in the second half of March before later stabilizing. The surge marked an escalation in the volume of activity targeting Roblox users.
Attackers began targeting users seeking Roblox cheats with fake Xeno Executor installers distributed through gaming forums and Discord communities. Bitdefender said the activity has affected users since the beginning of the year.
A threat research notice disclosed indicators of compromise for the fake Xeno/Powercat campaign, including domains, URLs, and multiple MD5 hashes. The notice also detailed the malware's Java-based stealer and RAT capabilities, including theft of browser, gaming, and crypto data plus remote-control features such as keylogging, webcam access, and PowerShell execution.
Bitdefender reported that newly observed infrastructure and expanded capabilities indicate the malware remains active and under development. The company assessed the fake Xeno activity as likely related to the previously documented Powercat campaign, but with upgraded capabilities and new command-and-control infrastructure.
Bitdefender said the fake Xeno malware activity is related to a campaign previously documented by ThreatLocker under the name Powercat. This establishes the earlier known malware family to which the current activity is linked.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetrojan-killer.net
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcecommunity.gurucul.com
Open sourcebleepingcomputer.com
Open sourcebitdefender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.