Fake Roblox Cheat Tool Hides Password Stealer and Remote Spy Software

Bitdefender says a months-long campaign is pushing booby-trapped copies of the Xeno script runner to Roblox players, planting malware that steals browser logins, drains crypto wallets and hands attackers full control of the PC.

ThreatVectr Newsdesk· 4 min read
Full-frame 16:9 photoreal editorial shot of a developer workstation at night, multiple monitors showing dense terminal output and an open code editor with a sus
Share

Key points

  • Bitdefender has tracked a campaign since January 2025 pushing fake copies of Xeno Executor, a popular Roblox cheat tool, to steal passwords and spy on victims.
  • The malware steals saved logins from Chrome, Edge, Brave, Opera and Vivaldi, plus Discord, Roblox and Minecraft account data.
  • It also targets cryptocurrency wallets, with dedicated code for Exodus Wallet.
  • Once installed, the payload gives attackers keylogging, screenshot capture, webcam access and a full remote shell on the victim's computer.
  • Bitdefender links the operation to the earlier "Powercat" campaign documented by ThreatLocker, now rebuilt with new servers and stronger tools.

Roblox players hunting for a way around the game's anti-cheat checks are being served malware instead.

Security firm Bitdefender says a campaign running since the start of 2025, and first reported by BleepingComputer, is pushing fake versions of Xeno Executor. The real tool is a third-party utility that lets players run custom scripts inside Roblox, often to automate actions or cheat. It is not made by Roblox, so the game regularly blocks it, and its authors keep releasing fresh builds to slip past detection.

That cat-and-mouse cycle is exactly what the attackers are exploiting.

How are players getting tricked?

Victims are lured through gaming forums, Discord servers and hijacked or impersonated accounts, all advertising an "undetected" build of Xeno. The download arrives as a ZIP file, or a self-extracting archive that unpacks itself, with instructions and a folder layout that mirrors the genuine tool. Some real Lua script files are even bundled in to make the package look convincing.

When the victim double-clicks xeno.exe, thinking it is the launcher, they run the first stage of the malware instead.

That loader checks whether Java is installed on the PC and quietly installs it if not. It then reads a small local file containing keys to reach the attackers' command-and-control server, the remote computer that issues orders to infected machines. A second file, disguised as decompiler.exe, is actually an obfuscated Java program that registers the new victim and pulls down the final payload.

What does the malware actually do?

A lot. The final stage is a Java-based remote access tool combined with an information stealer, and Bitdefender's writeup lays out a broad menu of abuse.

Capability What it means for the victim
Browser data theft Cookies and saved logins from Chrome, Edge, Brave, Opera and Vivaldi
Account theft Discord, Roblox, Minecraft and Microsoft Store tokens, plus stored payment details
Crypto theft Dedicated support for Exodus Wallet and detection of other wallets
Surveillance Keylogging, mouse tracking, screenshots, live desktop streaming, webcam access
Remote control File upload and download, PowerShell command execution, interactive shell

Stolen browser cookies are the quiet danger here. A session cookie can let an attacker walk straight into an account without ever seeing the password, which is why multi-factor authentication (a second check, usually a code or a tap on your phone) helps but does not always save you once a live session is hijacked. Honest answer: MFA would blunt password reuse attacks that follow, but it will not stop the initial cookie theft on the infected PC.

Bitdefender believes this is the same operation ThreatLocker previously tracked as "Powercat," now rebuilt with new servers and a beefier toolkit.

What should Roblox players and parents do?

Avoid third-party cheat tools entirely. That is the blunt advice from Bitdefender, and it is the right one. Anything advertised as an "undetected" bypass for Roblox's anti-cheat is a prime hiding place for malware, because the people downloading it have already decided to ignore warnings.

If a child in the household has run one of these installers, assume passwords saved in the browser are gone. Change the Roblox, Discord, Microsoft and email passwords from a different, clean device. Sign out of all active sessions in each account's security settings, check for unfamiliar logins, and run a full antivirus scan on the affected PC. If a crypto wallet was installed, move the funds from a clean machine and treat the old wallet as burned.

Indicators of compromise for network defenders are published in Bitdefender's report.

© 2026 Threat Vectr