Fake Xeno Executor installers are being used to trick Roblox players into installing malware that steals sensitive data and gives attackers remote access. Bitdefender says the campaign has evolved with new C2 infrastructure and a Java-based RAT/information stealer that targets browsers, game tokens, cryptocurrency wallets, and system surveillance features. #XenoExecutor #Bitdefender #Powercat #Roblox
Keypoints
- Fake Xeno Executor installers are being spread to Roblox users through forums, Discord, and impersonated accounts.
- The attackers disguise the payload as an βundetectedβ version of Xeno to attract players bypassing anti-cheat protections.
- The fake packages mimic legitimate Xeno files and launch a first-stage loader when users run xeno.exe.
- The final payload is a Java-based RAT and information stealer that harvests browser data, tokens, wallet information, and more.
- Bitdefender says the campaign is likely linked to previously documented Powercat activity, but with updated malware and new infrastructure.