The fake “undetected” Xeno Roblox executor currently circulating on gaming forums and Discord is a weaponized loader for the Powercat Java stealer, a multi‑stage RAT and infostealer that targets Discord, Roblox, Minecraft, crypto wallets and payment tokens while enabling full remote control of infected Windows systems.
Threat actors are promoting trojanized Xeno executors through Roblox‑focused forums, Discord communities, and likely compromised or impersonated accounts, advertising them as undetected builds that can bypass anti‑cheat checks.
The bundles arrive as ZIP archives or self‑extracting packages that closely mimic a legitimate Xeno installation, reusing genuine Lua scripts, plausible resource names and a familiar directory layout.
This convincing scaffolding is critical: players often children and teenagers believe they are installing a routine cheat, while in reality they are staging a Java‑based infection chain that has been previously documented under the Powercat family.
The primary entry point is a fake xeno.exe dropped under %LOCALAPPDATA%Xenoworkspacecache. Instead of launching the real Roblox executor, this binary acts as a loader.
It checks for a Java Runtime Environment under %LOCALAPPDATA%Javajrebinjavaw.exe and, if absent, silently extracts a bundled JRE via a hidden PowerShell command from an instance.exe archive, maintaining the illusion of a normal game utility.
The first stage then reads validation keys embedded in XenoIcon.jpg and invokes javaw.exe to run a second‑stage JAR masquerading as decompiler.exe.
This JAR is heavily obfuscated with Allatori, includes an anti‑analysis routine that inspects JVM arguments, debuggers and sandbox indicators, and phones home to the C2 at solthere[.]net endpoints to register the victim and redeem encrypted payloads.
Once the environment is deemed “clean,” the C2 returns a third‑stage payload that is written under %LOCALAPPDATA%MicrosoftGameDVR using DLL‑like names that resemble legitimate Windows components, abusing the Xbox Game Bar/Microsoft GameDVR directory to blend in.
Persistence is established via a Run‑key entry named Display Calibration, with startup approval toggled through Explorer’s StartupApproved registry path, allowing the stealer to survive reboots while hiding behind display‑related nomenclature.
The final stage is a Java‑based stealer and remote access trojan that extends far beyond generic credential theft.
It systematically enumerates “interesting” software Discord, Telegram, major browsers, Roblox and Minecraft launchers, VPN clients and popular crypto wallets including Exodus, Atomic and Cake Wallet then deploys tailored collection routines for each target.
Powercat Java Stealer
Bitdefender security researchers have identified a malware campaign targeting players searching for cheats for games such as Roblox. The campaign impersonates Xeno, a popular Roblox script executor used to automate actions and run custom scripts.
The malware verifies whether the disk partition size exceeds 20 GB, looks for well-known MAC addresses associated with emulated network adapters, checks the registry and WMI for virtual machine artifacts.

For Exodus wallet users, the malware specifically checks for version 26.1.5, unpacks app.asar, injects malicious JavaScript to weaken sandboxing and log sensitive buffers to SquirrelInteractive.bin, then parses and exfiltrates wallet tokens back to the C2.
Browser‑focused modules harvest cookies and user data from Chrome, Edge, Brave, Opera, Opera GX and Vivaldi, pulling authentication tokens and session material that can be reused for account takeover.
Discord tokens are extracted from browser storage and local client data, then used against the Discord API access to retrieve account details and stored payment methods, effectively bridging stealer functionality with live account interrogation.
Similar logic exists for Roblox and Minecraft accounts, including support for third‑party launchers such as Feather, Lunar and Modrinth.
The stealer also hunts Microsoft Store token broker files (.tbres) to steal payment‑related tokens tied to Microsoft accounts, amplifying potential financial impact.
Surveillance and remote‑access features elevate the threat from mere data theft to full compromise.
Using Java Native Access and COM/DirectShow interfaces, the malware can keylog, log mouse movements, capture screenshots, continuously stream the desktop at 500‑millisecond intervals, and access the webcam to stream live video to the C2.
It supports PowerShell‑based command execution, an interactive shell wired through WebSockets, file upload/download/rename operations and on‑the‑fly JAR updates pushed from the management domain.
Recent analyses by Bitdefender, ThreatLocker and other researchers show that this Powercat‑linked infrastructure has been active since early 2026, with infection volumes surging in the second half of March and remaining steady afterwards.
Newly observed C2 endpoints, refined anti‑sandbox checks and expanded wallet, browser and game‑launcher coverage all point to ongoing development rather than a one‑off campaign.
Because the lure is a Roblox cheat, a significant portion of victims are likely minors using shared family PCs, which dramatically raises the stakes: attackers can quietly harvest children’s gaming and chat accounts, spy through webcams.
IOCs
| MD5 | Description | |
| 4bdaf7792e908f163ebef137854c571d | archive containing fake Xeno installation | |
| 9930036e8f787674db39094e21413e77 | archive containing fake Xeno installation | |
| 9699bd6a448d0662a1e9e353223263b6 | archive containing fake Xeno installation | |
| 1a462c76efc4e73725b9e95c4a00fddb | archive containing fake Xeno installation | |
| 7b96170259a376ea79411c5713beb396 | archive containing fake Xeno installation | |
| 2ead73ed62f1c2beb9043ce92e774e0b | malicious xeno.exe loader | |
| 0aadd62b535e683a5a2fe31fde546d07 | malicious xeno.exe loader | |
| 26a94168fa25af0bcb46a18ede50af86 | malicious xeno.exe loader | |
| 0d03faf1764297c908158da77c8ffcae | malicious xeno.exe loader | |
| d123dbb5c5980bfeb22586197d2cc403 | decompiler.jar | |
| 163c8d117ef5a4e4e9c3e92a726af0eb | JAR file from GameDVR, third stage | |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Why use the 2026 Agentic SOC Buyer’s Guide? 8 Best Platforms Compared – Download the 2026 Buyer’s Guide

