At a glance
| Malware family | Powercat (Java-based stealer and RAT) |
| Threat actor | Not attributed to a named group; tracked as Powercat |
| Targets | Roblox players, including minors; also Discord and Minecraft users |
| Delivery vector | Fake “undetected” Xeno executor via forums, Discord, impersonated accounts |
| Key capabilities | Account and cookie theft, crypto-wallet theft, keylogging, screen streaming, webcam capture, PowerShell shell |
| Source | Bitdefender Labs |
TL;DR
Bitdefender found a fake Xeno Roblox cheat that installs a Java stealer. The Xeno Roblox malware steals gaming accounts, browser data, and crypto wallets. It also spies through the webcam and keyboard. Because the lure targets a young audience, families sharing a PC face real risk.
Delivery: a cheat that is really malware
The lure is a game cheat. Attackers advertise an “undetected” Xeno executor, a popular Roblox script tool. They post it on gaming forums and Discord servers. Some posts come from compromised or impersonated accounts. Because the real tool often gets blocked, an “undetected” build looks appealing. As Bitdefender puts it, the campaign “is directly affecting players looking to download a legitimate tool.” The fake download mimics a real Xeno folder, with copied Lua scripts and small junk files for cover.
How the infection chain works

The victim runs xeno.exe, believing it is the cheat. Instead, it is stage one. The loader checks for a bundled Java runtime and extracts one if needed. Next, it reads keys hidden inside a fake image file. Then it launches a Java archive disguised as a Windows program. That stage is obfuscated with a demo build of the Allatori tool.
First, the code fingerprints the machine and checks for sandboxes and debuggers. After those checks, it registers the victim with a control server and pulls the final payload. The stealer lands in a Windows GameDVR folder under a fake DLL name. This Xeno Roblox malware then tries a CMSTP trick to gain higher privileges.
The malware works hard to avoid analysis. It measures disk size, hunts for virtual-machine signs, and scans running processes for security tools. If it detects a sandbox, later stages simply stop. Before it calls home, it also fetches the victim’s rough location from public IP services. It then builds a unique machine ID from the hardware profile.
Command-and-control and data theft
The final stage is both a stealer and a remote access trojan. It builds its command-and-control address at runtime, using a hashed string and an unusual top-level domain. Traffic then runs over a WebSocket channel. Through it, operators can push updates or send tasks. The malware encrypts stolen data with AES and encodes it before upload.
Its reach is wide. As the report notes, “the final payload goes far beyond conventional credential theft.” It grabs cookies and Discord, Roblox, and Minecraft accounts. It also targets Exodus crypto wallets by tampering with local app files. On top of theft, it records keystrokes, captures screenshots twice a second, streams the desktop, and switches on the webcam. Operators can even open an interactive PowerShell shell for hands-on control.
The stealer casts a broad net across installed software. It maps crypto wallets, browsers, VPNs, and messaging apps. Targeted browsers include Brave, Chrome, Edge, Opera, and Vivaldi. It also pulls Discord tokens straight from browser databases. Then it queries the Discord API for saved payment methods. Microsoft Store token files are another prize. For persistence, it hides the launch command behind an innocent “Display Calibration” registry entry.
Attribution and scope
No named threat-actor group has claimed this campaign. Bitdefender links it to activity that ThreatLocker earlier tracked as Powercat. However, the new samples add capabilities and fresh C2 infrastructure. Microsoft has also reported related fake-Xeno RAT activity this year. Bitdefender did not publish a victim count. Instead, it reports infections since early 2026, with a sharp rise in the second half of March. The young audience makes the threat worse. The report warns the campaign “can attract children and teenagers,” who may expose family accounts and finances.
Defense and detection guidance
The best defense is simple: skip unofficial cheats. Bitdefender stresses that “avoiding unofficial cheats and executors” remains the strongest first step. Defenders can also hunt for clear artifacts. Watch for javaw.exe launched from a user’s LOCALAPPDATA path. Check the Run key value named “Display Calibration.” Look for a hidden -ntcache log in the home folder and a SquirrelInteractive.bin wallet log.
Beyond that, keep endpoint protection updated and turn on reputation-based blocking. Enable multi-factor authentication for gaming and Discord accounts. Application-control policies can block untrusted executables outright. Finally, talk with younger players about cheat scams.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.