Find notable cyber news and cases, enriched with sources, timelines, and signals.

Roblox fake Xeno Executor installer campaign

Campaign
First reported
Last updated
Happening score
H score 36
2 unique sources, 2 articles

Summary

Hide ▲

The fake Xeno Executor installer campaign is an active Roblox-themed malware operation that uses gaming forums and Discord communities to lure victims into running xeno.exe, which starts a loader chain ending in a Java-based RAT and information stealer. The payload can harvest browser cookies, Discord, Roblox, and Minecraft account data, along with cryptocurrency-wallet data, payment information, and other sensitive files. Researchers said the activity has been ongoing since the start of 2026, with a surge in the second half of March. The same reporting also notes it can record keystrokes, capture screenshots and webcam footage, stream the desktop, and allow remote shell access, extending the compromise beyond initial theft.

Related Happenings

Sandworm fake recruiter campaign targeting Ukrainian IT workers

Campaign
H score32 First: 11.08.2026 21:36 Last: 11.08.2026 21:36 Sources 1

About this happening: CERT-UA says UAC-0145, a cluster linked to Sandworm (APT44), has run a fake recruiter campaign against system administrators and IT professionals in Ukraine si...

Fake Xeno Executor Java RAT and infostealer malware

Malware Activity
H score30 First: 03.08.2026 22:25 Last: 03.08.2026 22:25 Sources 1

How related: The final payload is a Java-based RAT and information stealer malware that combines credential theft with surveillance and remote administration capabilities.

About this happening: Fake Xeno Executor installers are infecting Roblox players through gaming forums, Discord communities, and compromised or impersonated accounts, with victims runni...

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

UAT-11795 trojanized installer campaign targeting users across multiple countries

Campaign
H score35 First: 16.07.2026 13:19 Last: 16.07.2026 13:19 Sources 1

About this happening: The UAT-11795 campaign is using trojanized installers to spread Starland RAT and steal credentials and cryptocurrency from users in multiple countries. Activity has co...

UAT-11795 Starland RAT trojanized installer malware activity

Malware Activity
H score31 First: 16.07.2026 13:19 Last: 16.07.2026 13:19 Sources 1

About this happening: The UAT-11795 malware activity is using trojanized installers to deploy Starland RAT, putting credentials and cryptocurrency wallets at risk across multiple countries....

Timeline

  1. 03.08.2026 22:25 3 articles · 13d ago

    Fake Xeno Executor installers target Roblox players with RAT and infostealer malware

    Initial Disclosure

    Fake Xeno Executor installers targeting Roblox players have circulated since the start of the year, spiking in March before stabilizing; the lure is distributed through gaming forums, Discord communities, and compromised or impersonated accounts, and victims who launch xeno.exe trigger a loader chain that ends in a Java-based RAT and information stealer with browser-data theft, account-token theft, crypto-wallet theft, keylogging, screenshot capture, desktop streaming, webcam access, file transfer, PowerShell execution, and remote shell control.

    Show sources