Fake Xeno and Roblox Utilities Used to Install Windows RAT, Microsoft Warns
ID: e656fb1f-b618-516c-b27e-c314703938de
STIX ID: report--e656fb1f-b618-516c-b27e-c314703938de
Feed Name: HackRead
Microsoft Threat Intelligence observed a campaign that distributes trojanized gaming executables (e.g., Xeno.exe, RobloxPlayerBeta.exe) which act as downloaders to install a portable Java runtime and launch a malicious jd-gui.jar, ultimately deploying a remote access trojan. The attackers leverage PowerShell and trusted Windows binaries (LOLBins), persist via scheduled tasks and a startup script (world.vbs), and modify Microsoft Defender exclusions to evade detection; the report includes associated domains and endpoints for detection and blocking.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
