logo

Roblox Users Targeted with Tweaks Malware

ID: 40ad85fd-e12f-56ea-b968-dddb6d5d0945

STIX ID: report--40ad85fd-e12f-56ea-b968-dddb6d5d0945

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

**Executive Summary:** The report provides a technical analysis of the 'Tweaks' infostealer, documenting PowerShell and BAT-based data‑exfiltration to attacker webhooks, theft of Wi‑Fi profiles/passwords, collection of system and location data (UUID, username, public/private IP), and specific artifacts from two case studies (a BAT-based drop and a Discord-distributed EXE that drops a BAT in the Temp folder); actionable IOCs and TTPs include the PowerShell webhook calls, netsh commands for Wi‑Fi extraction, and the dropped BAT/Temp directory behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.