Fake Xeno Roblox Cheat Spreads Powercat RAT to Steal Accounts and Stream Desktops
A malicious campaign targeting Roblox players is distributing a fake version of the popular Xeno script executor that secretly installs an information stealer and remote access trojan (RAT).
Advertised as an “undetected” Roblox cheat through gaming forums and Discord communities, the trojanized package attempts to appear legitimate while providing attackers with extensive surveillance, credential theft, and remote-control capabilities.
Researchers say the operation is associated with malware previously tracked as Powercat and appears to remain under active development.
Fake Xeno Roblox Cheat Spreads Powercat RAT
The malicious package closely imitates the directory structure and filenames expected from a legitimate Xeno installation.
Attackers include genuine-looking Lua scripts alongside harmless decoy files to make the downloaded archive appear authentic.
Victims seeking Roblox cheat functionality are instructed to execute xeno.exe from a directory located under %LOCALAPPDATA%\Xeno\workspace\cache. Instead of launching the expected software, however, the executable initiates a multi-stage malware infection chain.
During the first stage, the loader determines whether Java is available on the compromised computer. If a suitable Java installation cannot be found, the malware can silently extract its own Java Runtime Environment into a local directory.
This approach ensures that subsequent Java-based payloads can execute even when Java was not previously installed by the victim.
The loader then extracts information concealed inside a file named XenoIcon.jpg and launches another Java archive disguised as decompiler.exe. This second-stage component performs extensive system reconnaissance and anti-analysis checks before continuing the infection.
According to researchers, the malware examines disk capacity, network adapter information, Windows Registry entries, running processes and other system characteristics.
These checks are designed to identify virtual machines, security sandboxes, debugging environments and other infrastructure commonly used by malware analysts. If suspicious characteristics are detected, the malware can terminate or avoid executing additional stages, making automated analysis more difficult.
After successfully passing its environmental checks, the malware communicates with attacker-controlled command-and-control (C2) infrastructure and downloads another payload.
The final Java component is placed under %LOCALAPPDATA%\Microsoft\GameDVR, using a directory name resembling legitimate Windows gaming functionality. DLL-like filenames provide an additional layer of disguise.
Persistence is established through a Windows Run Registry key using the name “Display Calibration.” This causes the malware to execute automatically whenever the compromised user logs into Windows.
Researchers also identified an update mechanism allowing operators to replace installed components with newer malware versions.
The final payload provides capabilities extending far beyond conventional credential stealing. Researchers found that it can capture screenshots approximately every 500 milliseconds and transmit them to attacker-controlled infrastructure. This effectively gives operators a near-live visual feed of activity occurring on the victim’s desktop.
Additional surveillance functionality includes keystroke recording, mouse monitoring and webcam access, while remote-command capabilities allow attackers to perform further actions on compromised machines.
The malware also targets sensitive browser information from Google Chrome, Microsoft Edge, Brave, Opera, Opera GX and Vivaldi. Browser cookies are particularly valuable because stolen session cookies can potentially enable account hijacking even when attackers do not possess the user’s password.
Gaming and communication accounts are another major target. The malware searches for Discord authentication tokens, Roblox cookies and Minecraft launcher information, potentially exposing user accounts, digital assets and payment-related information.
Stolen Discord sessions could additionally be abused to distribute malicious downloads to the victim’s contacts, expanding the campaign.
Two reported MD5 indicators associated with fake Xeno installation archives are 4bdaf7792e908f163ebef137854c571d and 9930036e8f787674db39094e21413e77. Security teams should hunt for suspicious Java execution originating from Xeno-related directories, unexpected files under Microsoft\GameDVR, and persistence entries named “Display Calibration.”
Roblox players should avoid unofficial cheat executors distributed through forums, Discord channels or file-sharing services.
The campaign demonstrates how attackers exploit gaming communities and trusted-looking software packages to transform supposedly harmless cheats into powerful remote surveillance and account-stealing malware.
No Comment! Be the first one.