Fake Xeno Roblox Cheat Spreads Powercat RAT to Steal Accounts, Wallets and Personal Data
A malware campaign targeting Roblox players is distributing a fake version of the Xeno script executor to infect Windows systems with a powerful remote access trojan (RAT) and information-stealing malware.
The malicious package is promoted as an “undetected” Xeno build and distributed through gaming forums, Discord communities, downloadable archives, and compromised accounts.
According to Bitdefender researchers, the operation uses a multi-stage Java-based infection chain designed to closely resemble a legitimate Xeno installation while ultimately deploying malware previously tracked as Powercat.
Fake Xeno Roblox Cheat Spreads Powercat RAT
The campaign is particularly concerning because Roblox cheats and script executors can attract younger users who may be less likely to recognize malicious downloads. ‘
Furthermore, gaming frequently takes place on shared household computers. A successful compromise could therefore expose far more than a Roblox account, potentially giving attackers access to browser sessions, Discord conversations, cryptocurrency wallets, payment information, personal files, screenshots, and webcam data belonging to multiple users.
The malicious archives reportedly reproduce the folder structure associated with legitimate Xeno distributions and include copied Lua scripts to make the package appear authentic.
Several files carry familiar-looking names while containing irrelevant or junk data. The supposed primary executable, xeno.exe, instead functions as the first-stage malware loader. Once executed, it checks whether Java is available by searching for %LOCALAPPDATA%\Java\jre\bin\javaw.exe.
If the required Java environment is unavailable, the loader can silently deploy a bundled Java Runtime Environment using hidden PowerShell execution.
This enables subsequent stages of the infection chain to operate without requiring victims to manually install Java. The resulting malware provides attackers with extensive information-stealing and remote-control capabilities that extend significantly beyond typical gaming credential theft.
Powercat can reportedly collect browser cookies and other sensitive user information from Google Chrome, Microsoft Edge, Brave, Opera, Opera GX, and Vivaldi.
The malware also targets credentials and authentication material associated with Discord, Roblox, Minecraft, Microsoft services, and cryptocurrency wallets.
For Discord, it can extract authentication tokens and query account information, potentially exposing saved payment-related details.
Roblox session cookies are another major target, potentially allowing attackers to hijack gaming accounts without obtaining passwords directly.
The malware also searches for information associated with multiple Minecraft launchers, including Lunar, Feather, Prism, Modrinth, Meteor, and the official Minecraft launcher.
Researchers additionally identified functionality specifically targeting Exodus cryptocurrency wallets, including code capable of modifying local application components and collecting wallet-related authentication data.
Beyond credential theft, the malware includes extensive surveillance functionality. Operators can capture keystrokes and mouse activity, take screenshots, enumerate connected displays, access webcams through Windows DirectShow components, and continuously stream desktop activity.
These capabilities effectively transform an infected gaming computer into a remotely controlled surveillance endpoint.The RAT also provides comprehensive file-management capabilities, allowing attackers to enumerate, upload, download, rename, or replace files.
It can execute Base64-encoded PowerShell commands and provide an interactive command shell, giving operators substantial control over compromised Windows systems.
Remote payload-update functionality further allows attackers to replace existing malware components as the campaign evolves.
Bitdefender reportedly observed changes in command-and-control infrastructure and additional functionality, suggesting that Powercat remains actively maintained.
Infection activity began earlier in the year, increased sharply during the second half of March, and subsequently continued at a relatively consistent rate.
Defenders should investigate suspicious Java execution originating from %LOCALAPPDATA%, review Windows Run registry entries named Display Calibration, and monitor endpoints for associated indicators of compromise.
Reported MD5 hashes include 4bdaf7792e908f163ebef137854c571d and 9930036e8f787674db39094e21413e77. Users should avoid unofficial Roblox executors, cheats, and “undetected” tools distributed through Discord, gaming forums, or untrusted archives.
Multi-factor authentication, updated endpoint protection, and regular session revocation can further reduce the impact of credential and account theft.
No Comment! Be the first one.