A fake Xeno Executor campaign is infecting Roblox players with malware that steals sensitive data and gives attackers remote control of compromised devices.
Cybersecurity company Bitdefender found the campaign targeting Roblox users from the start of the year. Activity rose sharply in March before settling at a lower level.
The attackers promote the malware as an undetected version of Xeno Executor. They target players who want a tool that can run scripts without triggering Roblox anti-cheat protections.
Attackers spread fake Xeno through gaming communities
Xeno Executor is a third-party Roblox utility that lets users automate actions or run custom scripts. Some players also use it to run cheats.
Roblox does not officially support the tool. The game client regularly blocks existing versions, which pushes Xeno’s developers to release new builds.
Attackers take advantage of that cycle. They distribute a fake Xeno Executor through gaming forums, Discord communities, and compromised or impersonated accounts.
Victims download ZIP files containing an installer and instructions. In other cases, the attackers use self-extracting archives that unpack the malicious files automatically.
The packages look convincing because they copy the directory structure of a legitimate Xeno installation. They also include genuine Lua scripts and use believable filenames.
However, when victims launch xeno.exe, they start the first-stage malware loader.
Malware installs a Java-based RAT
The loader first checks whether the device has a Java Runtime Environment. If Java is missing, the malware extracts its own copy.
It then reads a local file containing validation keys for the attackers’ command-and-control server. Next, it launches an obfuscated Java payload disguised as decompiler.exe.
That payload checks the infected system, registers the victim with the attackers’ infrastructure, and downloads the final malware.
The final payload combines a Java-based remote access trojan with an information stealer. It can collect credentials, monitor user activity, and give attackers extensive control over the infected computer.
Stolen data includes browser and payment information
The malware can steal cookies and other stored browser data from Chrome, Edge, Brave, Opera, and Vivaldi.
It also targets account and payment information linked to Discord, Roblox, Minecraft, and Microsoft Store accounts. In addition, it can steal cryptocurrency wallet data from Exodus Wallet and identify many other wallet applications.
Its surveillance features include:
- Keylogging and mouse activity tracking
- Screenshot capture and desktop streaming
- Webcam access
- File uploads and downloads
- PowerShell command execution
- Interactive remote shell access
Bitdefender believes the campaign is connected to Powercat, a threat cluster previously documented by ThreatLocker. However, the attackers have upgraded the malware and moved to new command-and-control infrastructure.
The fake Xeno Executor campaign shows why Roblox players should avoid downloading third-party tools from obscure sources. Installers promoted as undetected cheats or script tools can hide serious malware that puts accounts, payment data, and devices at risk.


0 responses to “Fake Xeno Executor Spreads Malware to Roblox Players”