Fake Roblox cheat tools are once again being weaponized, with a newly observed campaign distributing a sophisticated Java-based remote access trojan (RAT) disguised as an “undetected” version of the popular Xeno script executor.
Security researchers warn that the operation specifically targets gamers through Discord communities and underground forums, leveraging trust in widely used cheat utilities to deploy a multi-stage infection chain.
The operators continue to expand both infrastructure and capabilities, indicating ongoing development and active exploitation.
The infection begins with weaponized archives masquerading as legitimate Xeno installations. These packages replicate authentic directory structures and include decoy files such as LUA scripts to appear credible.
Victims are instructed to execute a binary located in the user’s local AppData path, which initiates the first stage of the attack.
Instead of launching a cheat engine, the executable checks for a local Java Runtime Environment and silently deploys one if absent using a concealed PowerShell command.
The second stage involves a heavily obfuscated Java archive disguised as a Windows executable. Using the Allatori obfuscator, the malware complicates static analysis while performing environment checks to evade debugging and sandbox detection.
It gathers system telemetry and communicates with a command-and-control (C2) server at domains such as registering the victim and retrieving additional payloads through encrypted requests.
The final stage delivers a fully featured Java RAT hidden within a directory mimicking Microsoft GameDVR, now associated with Xbox Game Bar.
This payload establishes persistence via registry Run keys under deceptive names like “Display Calibration” and attempts privilege escalation using CMSTP.
Once active, it connects to dynamically generated C2 infrastructure derived from hashed strings, enabling flexible and resilient communication.
According to analysis from Bitdefender and prior research by ThreatLocker, which tracked the malware as “Powercat”, the campaign has been active since early 2026, with a notable surge in infections beginning in mid-March.
Fake Xeno Roblox Cheats Java RAT
Unlike conventional commodity stealers, this malware combines credential harvesting with advanced surveillance and remote control capabilities.
It targets browser data from Chrome, Edge, Opera, and Brave, extracting cookies and stored credentials. It also specifically focuses on Discord, Roblox, and Minecraft accounts, parsing tokens and session data to enable account takeover.
The function responsible for communicating with the C2 server receives a message as a parameter, creates a JSON object from it.

Cryptocurrency wallets such as Exodus are actively tampered with through JavaScript injection, allowing attackers to capture live transaction data rather than relying solely on stored files.
Beyond data theft, the RAT introduces extensive monitoring features. It can log keystrokes and mouse activity, capture screenshots, stream the desktop in near real time, and access webcam feeds using DirectShow interfaces.
The malware also supports file exfiltration, upload, and modification, alongside execution of arbitrary PowerShell commands and interactive shell access, effectively granting attackers full control over compromised systems.
The campaign is particularly concerning due to its targeting of younger audiences within the Roblox ecosystem.
By exploiting interest in “undetected” cheats, attackers increase the likelihood of infecting shared household systems, exposing not only gaming accounts but also financial data, private communications, and potentially sensitive images captured via webcam surveillance.
Technical indicators suggest continuous evolution, including newly identified C2 endpoints and modular payload updates delivered over WebSocket connections.
The malware’s ability to dynamically replace components and execute commands in memory further complicates detection and remediation.
This campaign underscores a persistent trend in threat actor strategy: abusing gaming ecosystems as high-trust distribution channels for malware.
As cheat tools remain a common lure, users downloading unofficial executables from Discord or forums face significant risk, particularly when those tools promise to bypass detection mechanisms.
IOCs
| MD5 | Description | |
| 4bdaf7792e908f163ebef137854c571d | archive containing fake Xeno installation | |
| 9930036e8f787674db39094e21413e77 | archive containing fake Xeno installation | |
| 9699bd6a448d0662a1e9e353223263b6 | archive containing fake Xeno installation | |
| 1a462c76efc4e73725b9e95c4a00fddb | archive containing fake Xeno installation | |
| 7b96170259a376ea79411c5713beb396 | archive containing fake Xeno installation | |
| 2ead73ed62f1c2beb9043ce92e774e0b | malicious xeno.exe loader | |
| 0aadd62b535e683a5a2fe31fde546d07 | malicious xeno.exe loader | |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
$1M Data Breach Warranty is Genuine Protection?: Download 10 Point Free AI SOC Breach Warranty Guide

