A malware attack is targeting Roblox players with a deceptive version of the Xeno script executor tool This article explores theft stage malware. . The malicious package claims to be an "undetected" Xeno build and spreads through gaming forums, Discord communities, archives, and compromised accounts.

Researchers at Bitdefender revealed that this campaign employs a multi-stage Java-based infection chain designed to mimic a normal Xeno installation. Victims mistakenly believe they are installing a Roblox cheat but instead deploy a powerful remote access trojan (RAT) and information stealer previously identified as Powercat. An infected shared family computer could expose gaming accounts, Discord conversations, browser data, cryptocurrency wallets, payment information, webcam images, and personal documents. Fake Xeno Delivers JavaRAT Malicious archives mimic a legitimate Xeno folder structure and include copied Lua scripts to appear convincing.

Some files use familiar names but contain junk data, while the supposed main program, xeno.exe, is actually the first-stage loader. Beyond basic credential theft, this third-stage malware also collects cookies and user information from browsers like Chrome, Edge, Brave, Opera, Opera GX, and Vivaldi. Researchers discovered code that can modify local Exodus application files, weaken security settings, capture wallet-related data, and send valid tokens back to operators.

Attackers can log keystrokes and mouse movements, capture screenshots, stream the victim’s desktop every 500 milliseconds, list connected displays, and access the webcam through Windows DirectShow components.