Roblox fake Xeno Executor installer campaign
Campaign
Summary
Hide ▲
Show ▼
The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running xeno.exe, which starts a loader chain ending in a Java-based RAT and information stealer. The payload can harvest browser cookies, Discord, Roblox, and Minecraft account data, along with cryptocurrency-wallet data, payment information, and other sensitive files. Researchers said the activity has been ongoing since the start of 2026, with a surge in the second half of March. The same reporting also notes it can record keystrokes, capture screenshots and webcam footage, stream the desktop, and allow remote shell access, extending the compromise beyond initial theft.
Related Happenings
Sandworm fake recruiter campaign targeting Ukrainian IT workers
Campaign
H score32
First: 11.08.2026 21:36
Last: 11.08.2026 21:36
Sources 1
About this happening:
CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine si...
Sandworm fake recruiter campaign targeting Ukrainian IT workers
CampaignAbout this happening: CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine si...
Fake Xeno Executor Java RAT and infostealer malware
Malware Activity
H score30
First: 03.08.2026 22:25
Last: 03.08.2026 22:25
Sources 1
How related:
The final payload is a Java-based RAT and information stealer malware that combines credential theft with surveillance and remote administration capabilities.
About this happening:
Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...
Fake Xeno Executor Java RAT and infostealer malware
Malware ActivityHow related: The final payload is a Java-based RAT and information stealer malware that combines credential theft with surveillance and remote administration capabilities.
About this happening: Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
UAT-11795 trojanized installer campaign targeting users across multiple countries
Campaign
H score35
First: 16.07.2026 13:19
Last: 16.07.2026 13:19
Sources 1
About this happening:
The UAT-11795 campaign is using trojanized installers to spread Starland RAT and steal credentials and cryptocurrency from users in multiple countries. Activity has co...
UAT-11795 trojanized installer campaign targeting users across multiple countries
CampaignAbout this happening: The UAT-11795 campaign is using trojanized installers to spread Starland RAT and steal credentials and cryptocurrency from users in multiple countries. Activity has co...
UAT-11795 Starland RAT trojanized installer malware activity
Malware Activity
H score31
First: 16.07.2026 13:19
Last: 16.07.2026 13:19
Sources 1
About this happening:
The UAT-11795 malware activity is using trojanized installers to deploy Starland RAT, putting credentials and cryptocurrency wallets at risk across multiple countries....
UAT-11795 Starland RAT trojanized installer malware activity
Malware ActivityAbout this happening: The UAT-11795 malware activity is using trojanized installers to deploy Starland RAT, putting credentials and cryptocurrency wallets at risk across multiple countries....
Timeline
-
03.08.2026 22:25 3 articles · 13d ago
Fake Xeno Executor installers target Roblox players with RAT and infostealer malware
Initial DisclosureFake Xeno Executor installers targeting Roblox players have circulated since the start of the year, spiking in March before stabilizing; the lure is distributed through gaming forums, Discord communities, and compromised or impersonated accounts, and victims who launch xeno.exe trigger a loader chain that ends in a Java-based RAT and information stealer with browser-data theft, account-token theft, crypto-wallet theft, keylogging, screenshot capture, desktop streaming, webcam access, file transfer, PowerShell execution, and remote shell control.
Show sources
- Fake Roblox Xeno script launcher pushes infostealer, RAT malware — www.bleepingcomputer.com — 03.08.2026 22:25
- Fake Roblox Xeno script launcher pushes infostealer, RAT malware — www.bleepingcomputer.com — 03.08.2026 22:25
- Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access — thehackernews.com — 04.08.2026 16:11