Fake installers for the Roblox script tool Xeno Executor are infecting players with malware that combines remote-access and credential-theft capabilities, according to research from Bitdefender. The campaign has run since the start of the year, rose sharply in March, and is promoted through gaming forums, Discord communities, and compromised or impersonated accounts as an “undetected” version for bypassing Roblox anti-cheat.
Xeno Executor is a popular unofficial utility for running scripts in Roblox. Because it is not an official tool, the Roblox client periodically blocks its versions and the tool’s creators release new ones, which gives attackers a recurring supply of users actively seeking the newest build from wherever they can find it.
How the Fake Xeno Executor Packages Mimic the Legitimate Tool
Victims download ZIP archives containing fake installers and instructions, or self-extracting archives, that mimic the legitimate Xeno directory structure, include genuine Lua scripts, and use plausible filenames. The packages are designed to look routine to a player who has downloaded the tool before.
The Java Loader Chain Behind xeno.exe
Running xeno.exe launches a first-stage loader that checks for a Java Runtime Environment, extracting one if needed, then reads local C2 validation keys before launching an obfuscated Java payload disguised as decompiler.exe. That payload registers the victim and downloads the final payload, which Bitdefender describes as a Java-based RAT and info-stealer. The obfuscated Java staging is a deliberate choice: it puts the detection-heavy payload behind a generic-looking executable name and shifts the heavy lifting to a language runtime that is commonly present on gaming PCs.
The RAT’s Data-Theft and Remote-Control Capabilities
The final payload steals browser data — cookies and stored user data — from Chrome, Edge, Brave, Opera, and Vivaldi, and targets Discord, Roblox, Minecraft, and Microsoft Store tokens and payment data. It also steals crypto wallet data with dedicated Exodus Wallet support. On the remote-control side it provides keylogging, mouse logging, screenshots, desktop streaming, webcam access, file upload and download, PowerShell execution, and an interactive remote shell.
The Powercat Connection and Evidence of Continued Evolution
Bitdefender believes the campaign is the same as the “Powercat” activity previously documented by ThreatLocker, with significant capability updates and new command-and-control infrastructure. The relationship matters because it shows the operators rebuilt and expanded the toolset rather than starting fresh, a sign of sustained investment in the gaming-targeted malware niche.
Who the Campaign Targets and the Risks for Younger Players
The audience is Roblox players — a young, security-unaware base that is more likely to trust a script tool download from a Discord link or forum than to question its provenance. A full remote-control implant on those machines exposes everything else on the device, including payment and crypto assets. Bitdefender shared indicators of compromise and recommends players avoid installing third-party tools from obscure sources.
The Xeno campaign sits in a broader pattern of attackers using cheat tools, script utilities, and game enhancements as bait because the demand for them is constant and the audience is conditioned to accept risky installs. The shift from Powercat to a new Java RAT with updated C2 suggests the operators are planning for longevity, and the same lure mechanics can be repackaged around any other popular tool the moment Roblox blocks another version.
The decision to bundle webcam, desktop-streaming, and remote-shell access with data theft gives the operators a flexible toolchain: the same implant that harvests a Roblox token or a Minecraft payment method can later be used to record a screen or control a machine during a more targeted operation. For the players at risk, the malware’s breadth means the damage is not limited to the game credentials it was marketed against.
