GBHackers

Fake Xeno Roblox Cheats Deliver Java RAT That Steals Discord and Gaming Accounts


Fake Roblox cheat tools are once again being weaponized, with a newly observed campaign distributing a sophisticated Java-based remote access trojan (RAT) disguised as an “undetected” version of the popular Xeno script executor.

Security researchers warn that the operation specifically targets gamers through Discord communities and underground forums, leveraging trust in widely used cheat utilities to deploy a multi-stage infection chain.

The operators continue to expand both infrastructure and capabilities, indicating ongoing development and active exploitation.

The infection begins with weaponized archives masquerading as legitimate Xeno installations. These packages replicate authentic directory structures and include decoy files such as LUA scripts to appear credible.

Victims are instructed to execute a binary located in the user’s local AppData path, which initiates the first stage of the attack.

Instead of launching a cheat engine, the executable checks for a local Java Runtime Environment and silently deploys one if absent using a concealed PowerShell command.

The second stage involves a heavily obfuscated Java archive disguised as a Windows executable. Using the Allatori obfuscator, the malware complicates static analysis while performing environment checks to evade debugging and sandbox detection.

It gathers system telemetry and communicates with a command-and-control (C2) server at domains such as registering the victim and retrieving additional payloads through encrypted requests.

The final stage delivers a fully featured Java RAT hidden within a directory mimicking Microsoft GameDVR, now associated with Xbox Game Bar.

This payload establishes persistence via registry Run keys under deceptive names like “Display Calibration” and attempts privilege escalation using CMSTP.

Once active, it connects to dynamically generated C2 infrastructure derived from hashed strings, enabling flexible and resilient communication.

Java stealer killchain (Source : BitDefender).

According to analysis from Bitdefender and prior research by ThreatLocker, which tracked the malware as “Powercat”, the campaign has been active since early 2026, with a notable surge in infections beginning in mid-March.

Fake Xeno Roblox Cheats Java RAT

Unlike conventional commodity stealers, this malware combines credential harvesting with advanced surveillance and remote control capabilities.

It targets browser data from Chrome, Edge, Opera, and Brave, extracting cookies and stored credentials. It also specifically focuses on Discord, Roblox, and Minecraft accounts, parsing tokens and session data to enable account takeover.

The function responsible for communicating with the C2 server receives a message as a parameter, creates a JSON object from it.

Post request to C2 (Source : BitDefender).
Post request to C2 (Source : BitDefender).

Cryptocurrency wallets such as Exodus are actively tampered with through JavaScript injection, allowing attackers to capture live transaction data rather than relying solely on stored files.

Beyond data theft, the RAT introduces extensive monitoring features. It can log keystrokes and mouse activity, capture screenshots, stream the desktop in near real time, and access webcam feeds using DirectShow interfaces.

The malware also supports file exfiltration, upload, and modification, alongside execution of arbitrary PowerShell commands and interactive shell access, effectively granting attackers full control over compromised systems.

The campaign is particularly concerning due to its targeting of younger audiences within the Roblox ecosystem.

By exploiting interest in “undetected” cheats, attackers increase the likelihood of infecting shared household systems, exposing not only gaming accounts but also financial data, private communications, and potentially sensitive images captured via webcam surveillance.

Technical indicators suggest continuous evolution, including newly identified C2 endpoints and modular payload updates delivered over WebSocket connections.

The malware’s ability to dynamically replace components and execute commands in memory further complicates detection and remediation.

This campaign underscores a persistent trend in threat actor strategy: abusing gaming ecosystems as high-trust distribution channels for malware.

As cheat tools remain a common lure, users downloading unofficial executables from Discord or forums face significant risk, particularly when those tools promise to bypass detection mechanisms.

IOCs

MD5Description
4bdaf7792e908f163ebef137854c571darchive containing fake Xeno installation
9930036e8f787674db39094e21413e77archive containing fake Xeno installation
9699bd6a448d0662a1e9e353223263b6archive containing fake Xeno installation
1a462c76efc4e73725b9e95c4a00fddbarchive containing fake Xeno installation
7b96170259a376ea79411c5713beb396archive containing fake Xeno installation
2ead73ed62f1c2beb9043ce92e774e0bmalicious xeno.exe loader
0aadd62b535e683a5a2fe31fde546d07malicious xeno.exe loader

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

$1M Data Breach Warranty is Genuine Protection?: Download 10 Point Free AI SOC Breach Warranty Guide



Source link