Fake Roblox Cheat Tool Hides Password Stealer and Remote Spy Software

Bitdefender says a months-long campaign is pushing booby-trapped copies of the Xeno script runner to Roblox players, planting malware that steals browser logins, drains crypto wallets and hands attackers full control of the PC.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
Full-frame 16:9 photoreal editorial shot of a developer workstation at night, multiple monitors showing dense terminal output and an open code editor with a sus
Share

Key points

  • Bitdefender has tracked a campaign since January 2025 pushing fake copies of Xeno Executor, a popular Roblox cheat tool, to steal passwords and install remote-control software.
  • The malware steals saved logins from Chrome, Edge, Brave, Opera and Vivaldi, plus Discord, Roblox and Minecraft account data.
  • It also targets cryptocurrency wallets, with dedicated code for Exodus Wallet.
  • Once installed, the payload gives attackers keylogging, screenshot capture, webcam access and a full remote shell on the victim's computer.
  • Bitdefender links the operation to the earlier "Powercat" campaign documented by ThreatLocker, now rebuilt with new servers and a significantly upgraded toolkit.

Roblox players hunting for a way around the game's anti-cheat checks are being served malware instead.

Security firm Bitdefender says a campaign running since the start of 2025, and first reported by BleepingComputer, is pushing fake versions of Xeno Executor. The real tool is a third-party utility that lets players run custom scripts inside Roblox, often to automate actions or cheat. Roblox's client periodically blocks existing versions, so the tool's authors keep releasing fresh builds to slip past detection.

That cat-and-mouse cycle is exactly what the attackers are exploiting.

How are players getting tricked?

Victims are lured through gaming forums and hijacked or impersonated accounts advertising an "undetected" build of Xeno. Downloads arrive as ZIP archives or self-extracting packages, with a folder layout that mirrors the genuine tool. Some real Lua script files are bundled in to make the package look convincing.

When the victim double-clicks xeno.exe, thinking it's the launcher, they run the first stage of the malware instead.

That loader checks whether a Java Runtime Environment is installed and quietly extracts one if not. It then reads a small local file containing keys to reach the attackers' command-and-control server, the remote computer that issues orders to infected machines. A second file, disguised as decompiler.exe, is an obfuscated Java program that registers the new victim and pulls down the final payload.

What does the malware actually do?

Quite a lot. The final stage is a Java-based remote access tool combined with an information stealer, and Bitdefender's writeup lays out a broad menu of abuse.

Capability What it means for the victim
Browser data theft Cookies and saved logins from Chrome, Edge, Brave, Opera and Vivaldi
Account theft Discord, Roblox, Minecraft and Microsoft Store tokens, plus stored payment details
Crypto theft Dedicated support for Exodus Wallet and detection of other wallets
Surveillance Keylogging, mouse tracking, screenshots, live desktop streaming, webcam access
Remote control File upload and download, PowerShell command execution, interactive shell

Stolen browser cookies are the quiet danger here. A session cookie lets an attacker walk straight into an account without ever seeing the password, which is why multi-factor authentication (a second verification step, usually a code sent to your phone) helps but doesn't always save you once a live session is hijacked. MFA would blunt password-reuse attacks that follow, but it won't stop the initial cookie theft on an infected PC.

Bitdefender believes this is the same operation ThreatLocker previously tracked as "Powercat," now rebuilt with new servers and a beefier toolkit. It's a pattern we've seen in other Java-based RAT campaigns too: fake developer packages using the same remote-access approach turned up on the npm registry as recently as 3 August.

Should you worry if someone in your household plays Roblox?

Avoid third-party cheat tools entirely. That's the blunt advice from Bitdefender, and it's the right one. Anything advertised as an "undetected" bypass is a prime hiding place for malware, because anyone downloading it has already decided to ignore warnings.

If a child has run one of these installers, assume passwords saved in the browser are compromised. Change Roblox, Discord and email passwords from a clean device. Sign out of all active sessions in each account's security settings, check for unfamiliar logins, and run a full antivirus scan. If a crypto wallet was installed, move funds from a clean machine and treat the old wallet as burned.

Indicators of compromise for network defenders are published in Bitdefender's report.

© 2026 Threat Vectr