Fake Xeno Executor Java RAT and infostealer malware
Malware Activity
Updated: 03.08.2026 22:25
· First: 03.08.2026 22:25
· 📰 1 src / 1 articles
· H score: 29
The fake Xeno Executor loader chain is dropping a Java-based RAT and information stealer onto devices used by Roblox players, creating a high-risk path to credential theft and remote control. Victims run xeno.exe believing it is legitimate, but it launches an obfuscated Java stage and fetches the final payload. The malware steals browser cookies and stored data from Chrome, Edge, Brave, Opera, and Vivaldi, and targets Discord, Roblox, Minecraft, Microsoft Store tokens, and Exodus Wallet data. Its keylogging, screenshotting, webcam access, and remote shell features turn the infection into a full post-compromise surveillance platform.