Security researchers have uncovered an ongoing malware campaign that uses fake Roblox Xeno cheat tools to infect gamers with a powerful Java-based Remote Access Trojan (RAT).
The attackers are primarily targeting users through Discord servers and gaming forums, where fake cheat downloads are shared as legitimate software. By taking advantage of the popularity of Roblox cheats, the campaign aims to steal sensitive information and gain complete control of victims’ computers.
Researchers say the operation continues to evolve, with new infrastructure and malware capabilities being added regularly.
How the Attack Works
The infection starts when users download what appears to be a genuine Xeno Roblox cheat.
The downloaded archive looks convincing, containing realistic folder structures and harmless-looking files that make it appear authentic.
Instead of launching a game cheat, the installer quietly begins executing malicious code in the background.
If Java is not already installed on the system, the malware automatically installs a local Java Runtime Environment without the user’s knowledge. This prepares the system for the next stage of the attack.
Multi-Stage Malware Deployment
After the initial infection, the malware loads a heavily obfuscated Java application disguised as a normal Windows executable.
Before continuing, it performs several checks to determine whether it is running inside a virtual machine, sandbox, or debugging environment. These techniques help attackers avoid detection by security researchers.
The malware then collects basic system information and securely communicates with its command-and-control (C2) server to register the infected device and download additional malicious components.
Java RAT Gains Full System Access
The final payload is a Java Remote Access Trojan (RAT) hidden inside folders designed to resemble legitimate Microsoft GameDVR files associated with the Xbox Game Bar.
To remain active after a reboot, the malware creates registry Run entries using names that appear to be legitimate Windows components. It also attempts to obtain elevated privileges, allowing it to perform more advanced malicious activities.
Once established, the RAT connects to attacker-controlled servers and waits for further instructions.
What Information Does the Malware Target?
Unlike basic information-stealing malware, this campaign combines credential theft with powerful remote surveillance features.
The malware is capable of:
- Stealing saved passwords and browser cookies.
- Collecting credentials from Chrome, Edge, Opera, and Brave.
- Hijacking Discord, Roblox, and Minecraft accounts.
- Targeting cryptocurrency wallets, including Exodus.
- Capturing keystrokes and mouse activity.
- Taking screenshots.
- Streaming the victim’s desktop.
- Accessing webcam feeds.
- Uploading, downloading, and modifying files.
- Running PowerShell commands.
- Providing attackers with remote shell access.
These capabilities allow attackers to fully control an infected computer while collecting valuable personal and financial information.
Why Gamers Are Being Targeted
Researchers believe the campaign specifically targets Roblox players because many users search online for “free” or “undetected” cheat tools.
Young gamers are especially at risk, as they may download unofficial software from Discord communities or third-party websites without realizing it contains malware.
Since many gaming PCs are shared with family members, a successful infection could also expose banking information, personal documents, saved passwords, and private communications stored on the same device.
Malware Campaign Continues to Evolve
Security researchers, including Bitdefender and previous investigations by ThreatLocker, have linked the campaign to malware previously tracked as Powercat.
The operation has reportedly been active since early 2026 and continues to expand through new command-and-control servers and updated malware modules. The attackers also use encrypted communications and in-memory payload execution, making the malware more difficult to detect and remove.
How to Stay Protected
To reduce the risk of infection, users should follow these security best practices:
- Avoid downloading unofficial Roblox cheats or game modification tools.
- Only install software from trusted sources.
- Keep antivirus and security software up to date.
- Enable multi-factor authentication (MFA) on gaming and email accounts.
- Regularly update Windows and installed applications.
- Be cautious of download links shared through Discord servers or online gaming forums.
As cybercriminals increasingly target gaming communities, staying away from unofficial cheat software remains one of the most effective ways to avoid malware infections and protect personal information.
IOCs
| MD5 | Description | |
| 4bdaf7792e908f163ebef137854c571d | archive containing fake Xeno installation | |
| 9930036e8f787674db39094e21413e77 | archive containing fake Xeno installation | |
| 9699bd6a448d0662a1e9e353223263b6 | archive containing fake Xeno installation | |
| 1a462c76efc4e73725b9e95c4a00fddb | archive containing fake Xeno installation | |
| 7b96170259a376ea79411c5713beb396 | archive containing fake Xeno installation | |
| 2ead73ed62f1c2beb9043ce92e774e0b | malicious xeno.exe loader | |
| 0aadd62b535e683a5a2fe31fde546d07 | malicious xeno.exe loader | |