Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
ID: ee768d83-0a6b-5878-a363-5944dce416ee
STIX ID: report--ee768d83-0a6b-5878-a363-5944dce416ee
Feed Name: Bitdefender Labs
Bitdefender researchers describe an active malware campaign that lures gamers with a fake “undetected” Xeno Roblox script executor. The multi-stage Java infection chain installs a sophisticated stealer/RAT that can harvest browser cookies, Discord/Roblox/Minecraft accounts, cryptocurrency wallet data, payment tokens, and also perform keylogging, webcam capture, desktop streaming, file operations, PowerShell execution, persistence, and self-updating via C2 infrastructure; the report includes technical analysis, sandbox-evasion checks, persistence details, and IoCs (file hashes, URLs, and a dynamically generated C2 domain).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
