Fake Xeno Roblox Executor Delivers Powercat Java Stealer Through Discord
ID: 05e5016b-820d-5a08-8239-494ca32a12ae
STIX ID: report--05e5016b-820d-5a08-8239-494ca32a12ae
Feed Name: GBHackers
*Executive summary:* A trojanized Xeno Roblox executor is being distributed via gaming forums and Discord as an "undetected" cheat but acts as a multi‑stage loader for the Powercat Java stealer; the chain installs or extracts a bundled JRE, launches an Allatori‑obfuscated JAR that contacts C2 (solthere.net) to retrieve additional payloads, establishes persistence under GameDVR/Display Calibration, and delivers a Java RAT/stealer that harvests browsers, crypto wallets, gaming launchers, Discord tokens and can perform keylogging, screenshots, webcam streaming, and remote command execution — Bitdefender and other researchers report active operations since early 2026 and provide MD5 IOCs for archives, loaders and JARs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
