The campaign began at the start of the year and rose sharply in March before stabilizing, according to cybersecurity company Bitdefender.
Distribution: gaming forums, Discord, and compromised accounts
Bitdefender found the fake Xeno installers promoted directly to Roblox players through gaming forums, Discord communities, and via compromised or impersonated accounts that the threat actors controlled. The attackers advertise the malware as an "undetected" version of Xeno — a phrase intended to lure users seeking a build that will not be blocked by Roblox's anti-cheat protections.
Xeno Executor itself is a popular Roblox utility used to run custom scripts and cheats; it is not an official part of the Roblox client. Bitdefender notes the Roblox client periodically blocks existing Xeno versions, which forces legitimate Xeno creators to release new releases — a dynamic attackers exploit by claiming their packages will run undetected.
Infection chain: the fake "xeno.exe" and a staged Java loader
Victims receive ZIP archives containing fake Xeno installers and instructions, or self-extracting archives that unpack automatically. To appear authentic, the packages recreate the directory structure of a legitimate Xeno installation, include some genuine Lua scripts, and use plausible filenames.
When a user launches "xeno.exe" believing it to be the legitimate executor, they actually run the first-stage malware loader. That loader checks for a Java Runtime Environment and will extract a JRE if necessary. It reads a local file containing validation keys for the attackers' command-and-control (C2) server and then launches an obfuscated Java payload disguised as "decompiler.exe."
The obfuscated Java payload performs environment checks, registers the victim with the attackers' infrastructure, and downloads the final payload.

Built by Nubivance.
OSINTSights' secure edge-first architecture, AI content pipeline, and serverless ops are designed by Nubivance. We do this for clients too.
Talk to us →Final payload: a Java-based RAT and information stealer
The downloaded final payload is a Java-based remote-access Trojan (RAT) that combines credential theft with surveillance and remote administration capabilities. Bitdefender summarizes the malware's most important capabilities as follows:
- Steals browser data including cookies and other stored user data from Chrome, Edge, Brave, Opera, and Vivaldi.
- Targets online accounts and payment data, including Discord, Roblox, Minecraft, Microsoft Store tokens, and payment information associated with Discord and Microsoft Store accounts.
- Steals cryptocurrency wallet data, with dedicated functionality targeting Exodus Wallet and support for identifying numerous other cryptocurrency wallets.
- Provides surveillance capabilities, including keylogging, mouse activity logging, screenshot capturing, desktop streaming, and webcam access.
- Enables full remote control, allowing attackers to upload and download files, execute PowerShell commands, and access an interactive remote shell.
Linkage to "Powercat," new C2 infrastructure, and indicators shared
Bitdefender believes this campaign is the same one previously documented by ThreatLocker under the name "Powercat," but notes that the malware has significant updates and a new C2 infrastructure — a combination Bitdefender interprets as evidence of continuous evolution. The company has shared indicators of compromise (IoCs) for defenders to use.
What this means for Roblox players, security teams, and forum moderators
- Roblox players: Bitdefender's direct recommendation is clear — completely avoid installing third-party tools from obscure sources. Packages that claim to be "undetected" and arrive via forum posts or Discord messages should be treated as high risk.
- Security teams: Bitdefender's IoCs and the described multi-stage Java loader provide concrete forensic leads; teams should monitor for the specific behaviors Bitdefender documents, including the use of obfuscated Java binaries named "decompiler.exe" and local files containing validation keys for C2 communication.
- Forum moderators and Discord community managers: the campaign uses compromised or impersonated accounts to push its lure. Moderation controls, account verification, and rapid removal of posts advertising "undetected" executors will address a primary distribution vector identified by Bitdefender.
Bitdefender's report maps a complete, staged attack that preys on players seeking an advantage and converts that desire into a channel for broad surveillance and theft. The company has provided IoCs and a clear consumer recommendation: do not install third-party tools from obscure sources. Whether those steps will slow this campaign will depend on defenders acting on the technical indicators and on communities policing the distribution channels the attackers exploit.




