Fake Xeno Executor Java RAT and infostealer malware
Malware Activity
Summary
Hide ▲
Show ▼
Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims running xeno.exe and then an obfuscated Java payload disguised as decompiler.exe. The malware chain checks for a Java Runtime Environment, loads the final payload, and delivers a Java-based RAT and information stealer that can steal browser cookies, account tokens, crypto-wallet data, and provide remote access through PowerShell and an interactive shell. Bitdefender said the activity has been ongoing since the start of 2026, with a surge in the second half of March. The payload also targets Chrome, Edge, Brave, Opera, Vivaldi, Discord, Minecraft, and Exodus Wallet data, and includes keylogging, screenshot capture, webcam access, desktop streaming, and file manipulation.
Related Happenings
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware Activity
H score16
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
AmnesiaStealer macOS infostealer distributed via ClickFix
Malware ActivityAbout this happening: AmnesiaStealer is a Rust-based macOS infostealer spread through a counterfeit GitHub "Download for macOS" page and ClickFix-style lure. It steals Keychain, b...
ClickFix AmnesiaStealer distribution campaign targeting mac users
Campaign
H score22
First: 14.08.2026 13:45
Last: 14.08.2026 13:45
Sources 1
About this happening:
A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
ClickFix AmnesiaStealer distribution campaign targeting mac users
CampaignAbout this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...
Latest development: 16.08.2026 18:07
Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.
Roblox fake Xeno Executor installer campaign
Campaign
H score36
First: 03.08.2026 22:25
Last: 03.08.2026 22:25
Sources 1
How related:
The disclosure comes as Bitdefender warned of a separate campaign in which fake Xeno Executor installers promoted via gaming forums and Discord communities are used to initiate a multi-stage Java infection chain that drops an information stealer capable of credential theft, as well as stealing browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency-wallet data and payment information.
About this happening:
The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running...
Roblox fake Xeno Executor installer campaign
CampaignHow related: The disclosure comes as Bitdefender warned of a separate campaign in which fake Xeno Executor installers promoted via gaming forums and Discord communities are used to initiate a multi-stage Java infection chain that drops an information stealer capable of credential theft, as well as stealing browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency-wallet data and payment information.
About this happening: The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
UAT-11795 trojanized installer campaign targeting users across multiple countries
Campaign
H score35
First: 16.07.2026 13:19
Last: 16.07.2026 13:19
Sources 1
About this happening:
The UAT-11795 campaign is using trojanized installers to spread Starland RAT and steal credentials and cryptocurrency from users in multiple countries. Activity has co...
UAT-11795 trojanized installer campaign targeting users across multiple countries
CampaignAbout this happening: The UAT-11795 campaign is using trojanized installers to spread Starland RAT and steal credentials and cryptocurrency from users in multiple countries. Activity has co...
Timeline
-
03.08.2026 22:25 3 articles · 13d ago
Fake Xeno Executor installers infect Roblox players with a Java-based RAT
Initial DisclosureBitdefender said fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims running xeno.exe and then an obfuscated Java payload disguised as decompiler.exe. The malware chain checks for a Java Runtime Environment, loads the final payload, and delivers a Java-based RAT and information stealer that can steal browser cookies, account tokens, crypto-wallet data, and provide remote access through PowerShell and an interactive shell.
Show sources
- Fake Roblox Xeno script launcher pushes infostealer, RAT malware — www.bleepingcomputer.com — 03.08.2026 22:25
- Fake Roblox Xeno script launcher pushes infostealer, RAT malware — www.bleepingcomputer.com — 03.08.2026 22:25
- Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access — thehackernews.com — 04.08.2026 16:11