Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Fake Roblox Xeno script launcher pushes infostealer, RAT malware
Fake Xeno Executor installers are being used to trick Roblox players into installing malware that steals sensitive data and gives attackers remote access. Bitdefender says the campaign has evolved with new C2 infrastructure and a Java-based RAT/information stealer that targets browsers, game tokens, cryptocurrency wallets, and system surveillance features. #XenoExecutor #Bitdefender #Powercat #Roblox

Keypoints

  • Fake Xeno Executor installers are being spread to Roblox users through forums, Discord, and impersonated accounts.
  • The attackers disguise the payload as an β€œundetected” version of Xeno to attract players bypassing anti-cheat protections.
  • The fake packages mimic legitimate Xeno files and launch a first-stage loader when users run xeno.exe.
  • The final payload is a Java-based RAT and information stealer that harvests browser data, tokens, wallet information, and more.
  • Bitdefender says the campaign is likely linked to previously documented Powercat activity, but with updated malware and new infrastructure.

Read More: https://www.bleepingcomputer.com/news/security/fake-roblox-xeno-script-launcher-pushes-infostealer-rat-malware/