Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A sophisticated malware campaign targets Roblox players by distributing fake versions of the Xeno script executor through gaming forums and Discord communities. The attack deploys a multi-stage Java infection chain that mimics legitimate Windows and gaming components, including files disguised in Xbox Game Bar directories. The final payload functions as both an information stealer and remote access trojan, capable of stealing browser cookies, Discord, Roblox, and Minecraft accounts, cryptocurrency wallets, and payment data. Beyond typical credential theft, it records keystrokes, accesses webcams, streams desktops, manipulates files, executes PowerShell commands, and provides attackers with interactive system control. Previously documented as Powercat, the malware continues active development with new command-and-control infrastructure. Activity increased significantly in March 2026, particularly threatening children and teenagers who may expose personal accounts, webcam images, and financial information fr...
AI Analysis
Technical Summary
This threat involves a sophisticated malware campaign distributing fake versions of the Xeno script executor targeting Roblox players through Discord and gaming forums. The infection chain is multi-stage, leveraging Java components and masquerading as legitimate Windows and Xbox Game Bar files. The final payload operates as both an information stealer and remote access trojan, capable of exfiltrating browser cookies, Discord, Roblox, Minecraft accounts, cryptocurrency wallets, and payment data. It also performs keystroke logging, webcam access, desktop streaming, file manipulation, PowerShell command execution, and interactive system control. Known previously as Powercat, the malware continues active development with updated command-and-control infrastructure. The campaign's activity surged in March 2026, with a focus on exploiting younger users who may inadvertently expose sensitive personal and financial information.
Potential Impact
The malware can steal sensitive credentials and financial data, including browser cookies, gaming accounts, cryptocurrency wallets, and payment information. It enables attackers to monitor victims via webcam and keystroke logging, stream desktops, manipulate files, and execute arbitrary commands remotely. This level of access can lead to significant privacy violations, financial loss, and persistent system compromise. The targeting of children and teenagers increases the risk of exposure of personal and financial data of vulnerable users.
Mitigation Recommendations
No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Users should avoid downloading or running unofficial or fake versions of software, especially from untrusted sources such as unofficial Discord servers or gaming forums. Security awareness training focused on recognizing fake executables and phishing attempts is recommended. Use of reputable antivirus and endpoint protection solutions that can detect and block this malware is advised. Monitor for suspicious activity related to account access and financial transactions. Since this is an active malware campaign, timely user education and cautious behavior are the primary mitigations.
Indicators of Compromise
- domain: ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz
- hash: 0aadd62b535e683a5a2fe31fde546d07
- hash: 0d03faf1764297c908158da77c8ffcae
- hash: 163c8d117ef5a4e4e9c3e92a726af0eb
- hash: 26a94168fa25af0bcb46a18ede50af86
- hash: 2ead73ed62f1c2beb9043ce92e774e0b
- hash: 1a462c76efc4e73725b9e95c4a00fddb
- hash: 4bdaf7792e908f163ebef137854c571d
- hash: 7b96170259a376ea79411c5713beb396
- hash: 9699bd6a448d0662a1e9e353223263b6
- hash: 9930036e8f787674db39094e21413e77
- hash: d123dbb5c5980bfeb22586197d2cc403
- hash: 000dcd8d78a97b9f78f872fea559f9b1706f0bc2
- hash: 4a4c6265d2f80d9b833f141a7f841349de94ccf5
- hash: 6525189bce7adf3bb3b84906ffd1e27cdc111bd9
- hash: 86dc6db6e8c67644e8c4c84656c92937a347777c
- hash: de74e45ff4f99c385d1ec91d4f6a197fc90845b0
- hash: 27655272c15d508ce4d33cdae686e4b1ba05877fae5ba2c557da437c47cf0957
- hash: 609b1004d90f85936d56e507b3220796103d201b8e7677ee3e82872e5b4aa73f
- hash: 9b2e33ae75f419facf56f321b3f2447b83b76d6c1d9b29fcde41c7d65c321dce
- hash: bf973513f76a24d92c4953d8c9540d427234107afa9881f4e62b55c79c5bf7cb
- hash: c08a0d5b30b1088284a3c473279eb59557de517e7d8662495272b22634c8b5ed
- url: https://solthere.net/justacoolkat10
- url: https://solthere.net/api/v1/redeem
- hash: 10f634c18e75faf733a834ee6fd1997b3cf25700
- hash: 1b93e05e58e5aa32aaf18d58b888a008d5a35341
- hash: 21bd2be3535cfe40b652290a3a94e4538e31885e
- hash: 362458ae08945378f2ea9fd2bb31e3ae5382d79d
- hash: 997dae041966070f26aa7bb1b8ab663fb8609678
- hash: c4d541e31cef2ccccd57d27e5cc6997c4d52020a
- hash: 16f38cf540bcb045ae03d310c13c068718f1d23b2bb7b893deb86ff880c1c599
- hash: 1f0ceed271a42b0c8eaaa9966b0152a7a1e7ccc1534be23b02c8ef5ab239efdb
- hash: 3b500f46ce6dc31ad635c6b511462a31b632ee531d9e102084413af016102c98
- hash: 6195dda8339036ad74fd4fb185c5fc02eb28270faa2b41ec3d9303cba7e8d2c6
- hash: 7aa2ddc2a6f3c97723dc3a882f481398dd575401b3bb7a4f4c1939d2990e8418
- hash: 879f5aac13722af56c2fb7b0bc31a2ae318356aafdfe93274e23a32e494fd0f2
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
Description
A sophisticated malware campaign targets Roblox players by distributing fake versions of the Xeno script executor through gaming forums and Discord communities. The attack deploys a multi-stage Java infection chain that mimics legitimate Windows and gaming components, including files disguised in Xbox Game Bar directories. The final payload functions as both an information stealer and remote access trojan, capable of stealing browser cookies, Discord, Roblox, and Minecraft accounts, cryptocurrency wallets, and payment data. Beyond typical credential theft, it records keystrokes, accesses webcams, streams desktops, manipulates files, executes PowerShell commands, and provides attackers with interactive system control. Previously documented as Powercat, the malware continues active development with new command-and-control infrastructure. Activity increased significantly in March 2026, particularly threatening children and teenagers who may expose personal accounts, webcam images, and financial information fr...
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This threat involves a sophisticated malware campaign distributing fake versions of the Xeno script executor targeting Roblox players through Discord and gaming forums. The infection chain is multi-stage, leveraging Java components and masquerading as legitimate Windows and Xbox Game Bar files. The final payload operates as both an information stealer and remote access trojan, capable of exfiltrating browser cookies, Discord, Roblox, Minecraft accounts, cryptocurrency wallets, and payment data. It also performs keystroke logging, webcam access, desktop streaming, file manipulation, PowerShell command execution, and interactive system control. Known previously as Powercat, the malware continues active development with updated command-and-control infrastructure. The campaign's activity surged in March 2026, with a focus on exploiting younger users who may inadvertently expose sensitive personal and financial information.
Potential Impact
The malware can steal sensitive credentials and financial data, including browser cookies, gaming accounts, cryptocurrency wallets, and payment information. It enables attackers to monitor victims via webcam and keystroke logging, stream desktops, manipulate files, and execute arbitrary commands remotely. This level of access can lead to significant privacy violations, financial loss, and persistent system compromise. The targeting of children and teenagers increases the risk of exposure of personal and financial data of vulnerable users.
Defensive Guidance
No official patch or remediation is available as this is a malware campaign rather than a software vulnerability. Users should avoid downloading or running unofficial or fake versions of software, especially from untrusted sources such as unofficial Discord servers or gaming forums. Security awareness training focused on recognizing fake executables and phishing attempts is recommended. Use of reputable antivirus and endpoint protection solutions that can detect and block this malware is advised. Monitor for suspicious activity related to account access and financial transactions. Since this is an active malware campaign, timely user education and cautious behavior are the primary mitigations.
Technical Details
- Author
- AlienVault
- Tlp
- white
- References
- ["https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor"]
- Adversary
- null
- Pulse Id
- 6a722d8ce0ae0afdde284102
- Threat Score
- null
Indicators of Compromise
Domain
| Value | Description | Copy |
|---|---|---|
domaince953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash0aadd62b535e683a5a2fe31fde546d07 | — | |
hash0d03faf1764297c908158da77c8ffcae | — | |
hash163c8d117ef5a4e4e9c3e92a726af0eb | — | |
hash26a94168fa25af0bcb46a18ede50af86 | — | |
hash2ead73ed62f1c2beb9043ce92e774e0b | — | |
hash1a462c76efc4e73725b9e95c4a00fddb | — | |
hash4bdaf7792e908f163ebef137854c571d | — | |
hash7b96170259a376ea79411c5713beb396 | — | |
hash9699bd6a448d0662a1e9e353223263b6 | — | |
hash9930036e8f787674db39094e21413e77 | — | |
hashd123dbb5c5980bfeb22586197d2cc403 | — | |
hash000dcd8d78a97b9f78f872fea559f9b1706f0bc2 | — | |
hash4a4c6265d2f80d9b833f141a7f841349de94ccf5 | — | |
hash6525189bce7adf3bb3b84906ffd1e27cdc111bd9 | — | |
hash86dc6db6e8c67644e8c4c84656c92937a347777c | — | |
hashde74e45ff4f99c385d1ec91d4f6a197fc90845b0 | — | |
hash27655272c15d508ce4d33cdae686e4b1ba05877fae5ba2c557da437c47cf0957 | — | |
hash609b1004d90f85936d56e507b3220796103d201b8e7677ee3e82872e5b4aa73f | — | |
hash9b2e33ae75f419facf56f321b3f2447b83b76d6c1d9b29fcde41c7d65c321dce | — | |
hashbf973513f76a24d92c4953d8c9540d427234107afa9881f4e62b55c79c5bf7cb | — | |
hashc08a0d5b30b1088284a3c473279eb59557de517e7d8662495272b22634c8b5ed | — | |
hash10f634c18e75faf733a834ee6fd1997b3cf25700 | — | |
hash1b93e05e58e5aa32aaf18d58b888a008d5a35341 | — | |
hash21bd2be3535cfe40b652290a3a94e4538e31885e | — | |
hash362458ae08945378f2ea9fd2bb31e3ae5382d79d | — | |
hash997dae041966070f26aa7bb1b8ab663fb8609678 | — | |
hashc4d541e31cef2ccccd57d27e5cc6997c4d52020a | — | |
hash16f38cf540bcb045ae03d310c13c068718f1d23b2bb7b893deb86ff880c1c599 | — | |
hash1f0ceed271a42b0c8eaaa9966b0152a7a1e7ccc1534be23b02c8ef5ab239efdb | — | |
hash3b500f46ce6dc31ad635c6b511462a31b632ee531d9e102084413af016102c98 | — | |
hash6195dda8339036ad74fd4fb185c5fc02eb28270faa2b41ec3d9303cba7e8d2c6 | — | |
hash7aa2ddc2a6f3c97723dc3a882f481398dd575401b3bb7a4f4c1939d2990e8418 | — | |
hash879f5aac13722af56c2fb7b0bc31a2ae318356aafdfe93274e23a32e494fd0f2 | — |
Url
| Value | Description | Copy |
|---|---|---|
urlhttps://solthere.net/justacoolkat10 | — | |
urlhttps://solthere.net/api/v1/redeem | — |
Threat ID: 6a72fe44bf8831d5399b177d
Added to database: 08/05/2026, 09:11:32 UTC
Last enriched: 08/05/2026, 11:29:18 UTC
Last updated: 08/05/2026, 13:58:02 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.