Bitdefender researchers uncovered a Java-based malware campaign that impersonates an “undetected” Xeno Roblox script executor and spreads through gaming forums and Discord communities. The payload steals browser cookies, Discord, Roblox and Minecraft accounts, crypto-wallet and payment data, while also enabling keylogging, webcam access, desktop streaming, file manipulation, PowerShell execution, and remote control. #Xeno #Roblox #Discord #Minecraft #Powercat #Exodus
Keypoints
- The malware is distributed as a fake “undetected” version of the Xeno Roblox script executor.
- It is promoted through gaming forums and Discord communities, including compromised or impersonated accounts.
- The infection chain is multi-stage and Java-based, with files and directories designed to look like legitimate Windows and gaming components.
- The final payload functions as a stealer and remote access trojan, combining theft, surveillance, persistence, and command execution.
- Targets include browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency wallets, and payment-related information.
- Researchers identified new command-and-control infrastructure and added capabilities, indicating ongoing development of the malware, previously documented as Powercat.
- Activity has been present since the beginning of the year and increased sharply in the second half of March.
MITRE Techniques
- [T1204 ] User Execution – Victims are tricked into running the fake cheat package and launching the malicious loader (‘run the main entry point located at %LOCALAPPDATA%Xenoworkspacecachexeno.exe’).
- [T1027 ] Obfuscated Files or Information – The JAR bytecode is obfuscated with Allatori to hinder analysis (‘Its Java bytecode is obfuscated with the demo version of Allatori’).
- [T1497 ] Virtualization/Sandbox Evasion – The malware checks for sandbox and VM artifacts before proceeding (‘looks for traces of debugging, artifacts that indicate sandbox execution’).
- [T1057 ] Process Discovery – It iterates over running processes to detect monitoring tools used in analysis environments (‘iterates over running processes to detect monitoring tools’).
- [T1016 ] System Network Configuration Discovery – It contacts IP geolocation services to obtain location data and build a victim identifier (‘contacts two online services that can identify IP addresses’).
- [T1105 ] Ingress Tool Transfer – The server sends updated JAR payloads that are written to disk and executed (‘The server can also send … an updated JAR file’).
- [T1547.001 ] Registry Run Keys / Startup Folder – Persistence is established through the Windows Run key (‘adds the command line … to the SoftwareMicrosoftWindowsCurrentVersionRun registry key’).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task – The malware uses startup-approved persistence mechanisms associated with Windows startup behavior (‘enabling the Run entry’).
- [T1055 ] Process Injection – It attempts to move execution into a CMSTP process with elevated privileges (‘attempts to move execution to a CMSTP process with elevated privileges’).
- [T1059.001 ] Command and Scripting Interpreter: PowerShell – PowerShell is used to extract Java, run commands, and execute Base64-encoded instructions (‘launches a PowerShell process’, ‘executes a Base64-encoded command’).
- [T1059.005 ] Command and Scripting Interpreter: Visual Basic – Not mentioned.
- [T1056.001 ] Keylogging – It records keyboard activity and hooks input events (‘can record keystrokes’, ‘register hooks for mouse and keyboard events’).
- [T1113 ] Screen Capture – It captures screenshots and can stream the display (‘capture individual screenshots’, ‘streaming mode that captures a screenshot every 500 milliseconds’).
- [T1123 ] Audio Capture – Not mentioned.
- [T1125 ] Video Capture – Webcam capture is performed and streamed to the C2 server (‘webcam capture … streamed to the C2 server’).
- [T1074.001 ] Local Data Staging: Local Data Staging – Logged wallet data is written to a local file before exfiltration (‘logs wallet-related buffers to a file named SquirrelInteractive.bin’).
- [T1005 ] Data from Local System – The malware searches local files, databases, and directories for tokens, cookies, and wallet data (‘extracts information stored by each of them’).
- [T1041 ] Exfiltration Over C2 Channel – Stolen data and buffers are sent to the command-and-control server (‘sent to the C2 server’).
- [T1021.001 ] Remote Services: Remote Desktop Protocol – Not mentioned.
- [T1219 ] Remote Access Software – The malware provides interactive shell and full remote control capabilities (‘give attackers interactive control of the infected computer’).
- [T1053.005 ] Scheduled Task/Job: Scheduled Task – Not mentioned.
- [T1106 ] Native API – It uses Java Native Access and Windows APIs for mouse/keyboard hooks (‘interact with Windows functions from User32’).
- [T1105 ] Ingress Tool Transfer – It downloads and writes updated malware versions to the GameDVR directory (‘writes the third stage to %LOCALAPPDATA%MicrosoftGameDVR’).
Indicators of Compromise
- [MD5 hashes] malicious archives/loaders and payloads – 4bdaf7792e908f163ebef137854c571d, 2ead73ed62f1c2beb9043ce92e774e0b, and other 10 items
- [URLs] C2 registration and payload retrieval – hxxps://solthere[.]net/justacoolkat10, hxxps://solthere[.]net/api/v1/redeem
- [Domain] dynamically generated command-and-control host – ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a[.]xyz
- [File names] malware stages and staged payloads – xeno.exe, decompiler.exe, instance.exe, and SquirrelInteractive.bin
- [Windows paths] staging and persistence locations – %LOCALAPPDATA%Xenoworkspacecachexeno.exe, %LOCALAPPDATA%MicrosoftGameDVR
- [Registry keys] persistence entries – SoftwareMicrosoftWindowsCurrentVersionRun, SoftwareMicrosoftWindowsCurrentVersionExplorerStartupApprovedRun
- [Network-related domains] stolen-data and token targets – discord[.]com, ipapi[.]co, ipwho[.]is
Read more: https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor