logo

Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums

ID: ee768d83-0a6b-5878-a363-5944dce416ee

STIX ID: report--ee768d83-0a6b-5878-a363-5944dce416ee

Feed Name: Bitdefender Labs

Threat Score
75/100

Date Published: 2026-08-03

Date Updated: 2026-08-04

Author: Janos Gergo SZELES

...
...

Bitdefender researchers describe an active malware campaign that lures gamers with a fake “undetected” Xeno Roblox script executor. The multi-stage Java infection chain installs a sophisticated stealer/RAT that can harvest browser cookies, Discord/Roblox/Minecraft accounts, cryptocurrency wallet data, payment tokens, and also perform keylogging, webcam capture, desktop streaming, file operations, PowerShell execution, persistence, and self-updating via C2 infrastructure; the report includes technical analysis, sandbox-evasion checks, persistence details, and IoCs (file hashes, URLs, and a dynamically generated C2 domain).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.