logo

Fake Xeno and Roblox Utilities Used to Install Windows RAT, Microsoft Warns

ID: e656fb1f-b618-516c-b27e-c314703938de

STIX ID: report--e656fb1f-b618-516c-b27e-c314703938de

Feed Name: HackRead

Threat Score
70/100

Date Published: 2026-03-01

Date Updated: 2026-04-22

Author: Waqas

...
...

Microsoft Threat Intelligence observed a campaign that distributes trojanized gaming executables (e.g., Xeno.exe, RobloxPlayerBeta.exe) which act as downloaders to install a portable Java runtime and launch a malicious jd-gui.jar, ultimately deploying a remote access trojan. The attackers leverage PowerShell and trusted Windows binaries (LOLBins), persist via scheduled tasks and a startup script (world.vbs), and modify Microsoft Defender exclusions to evade detection; the report includes associated domains and endpoints for detection and blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.