logo

Fake Xeno Roblox Executor Delivers Powercat Java Stealer Through Discord

ID: 05e5016b-820d-5a08-8239-494ca32a12ae

STIX ID: report--05e5016b-820d-5a08-8239-494ca32a12ae

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-08-06

Date Updated: 2026-08-06

Author: Mayura Kathir

...
...

*Executive summary:* A trojanized Xeno Roblox executor is being distributed via gaming forums and Discord as an "undetected" cheat but acts as a multi‑stage loader for the Powercat Java stealer; the chain installs or extracts a bundled JRE, launches an Allatori‑obfuscated JAR that contacts C2 (solthere.net) to retrieve additional payloads, establishes persistence under GameDVR/Display Calibration, and delivers a Java RAT/stealer that harvests browsers, crypto wallets, gaming launchers, Discord tokens and can perform keylogging, screenshots, webcam streaming, and remote command execution — Bitdefender and other researchers report active operations since early 2026 and provide MD5 IOCs for archives, loaders and JARs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.