Find notable cyber news and cases, enriched with sources, timelines, and signals.

Fake Xeno Executor Java RAT and infostealer malware

Malware Activity
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

The fake Xeno Executor loader chain is dropping a Java-based RAT and information stealer onto devices used by Roblox players, creating a high-risk path to credential theft and remote control. Victims run xeno.exe believing it is legitimate, but it launches an obfuscated Java stage and fetches the final payload. The malware steals browser cookies and stored data from Chrome, Edge, Brave, Opera, and Vivaldi, and targets Discord, Roblox, Minecraft, Microsoft Store tokens, and Exodus Wallet data. Its keylogging, screenshotting, webcam access, and remote shell features turn the infection into a full post-compromise surveillance platform.

Related Happenings

Roblox fake Xeno Executor installer campaign

Campaign
H score36 First: 03.08.2026 22:25 Last: 03.08.2026 22:25 Sources 1

How related: Cybersecurity company Bitdefender discovered a campaign targeting Roblox users since the start of the year, rising sharply in March before stabilizing.

About this happening: The fake Xeno Executor installer campaign is spreading malware to Roblox players, putting account data, payment details, and remote access at risk. Operators push the...

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

CrashStealer macOS information stealer activity

Malware Activity
H score10 First: 13.07.2026 20:36 Last: 13.07.2026 20:36 Sources 1

About this happening: CrashStealer is a macOS information-stealing malware that was tracked in May and seen in attacks in early July. It impersonates Apple's crash-reporting tool by...

Windows cryptocurrency clipper malware using USB LNK worming and Tor C2

Malware Activity
H score29 First: 18.06.2026 17:30 Last: 18.06.2026 17:30 Sources 1

About this happening: A Windows-based cryptocurrency clipper has been active since February 2026, using USB-delivered LNK worming to steal wallet data and reroute payments. The malware adds...

WeedHack Minecraft MaaS campaign expands with malicious JARs and remote access

Malware Activity
H score65 First: 03.06.2026 00:54 Last: 03.06.2026 00:54 Sources 1

About this happening: WeedHack is a Minecraft-focused malware-as-a-service operation that has been active since January 2026 and uses SEO poisoning and YouTube to push malicious dow...

Timeline

  1. 03.08.2026 22:25 2 articles · 0h ago

    Fake Xeno Executor installers infect Roblox players with a Java-based RAT

    Initial Disclosure

    Bitdefender said fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims running xeno.exe and then an obfuscated Java payload disguised as decompiler.exe. The malware chain checks for a Java Runtime Environment, loads the final payload, and delivers a Java-based RAT and information stealer that can steal browser cookies, account tokens, crypto-wallet data, and provide remote access through PowerShell and an interactive shell.

    Show sources