logo

Fake Xeno Roblox Executor Delivers Java RAT Through Discord and Gaming Forums

ID: 5b65eb03-6370-5698-bed7-51e5c523da3f

STIX ID: report--5b65eb03-6370-5698-bed7-51e5c523da3f

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: Varshini

...
...

A malicious campaign is distributing a fake “undetected” Xeno Roblox script executor via forums, Discord, archives, and compromised accounts; the installer uses a multi-stage Java-based loader (including an embedded JRE) to deploy a Powercat JavaRAT that steals browser cookies, Roblox/Discord/Minecraft tokens, cryptocurrency wallet data, and can log keystrokes, capture screenshots and webcam, stream the desktop, and provide remote shell/file operations. Bitdefender observed active development and new C2 infrastructure, and recommends blocking the identified infrastructure, hunting for suspicious Java execution under %LOCALAPPDATA%\, reviewing Run-key entries named Display Calibration, avoiding unofficial cheats, enabling MFA, and using updated endpoint protection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.