Find notable cyber news and cases, enriched with sources, timelines, and signals.

Roblox fake Xeno Executor installer campaign

Campaign
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

The fake Xeno Executor installer campaign is spreading malware to Roblox players, putting account data, payment details, and remote access at risk. Operators push the lure through gaming forums, Discord communities, and compromised or impersonated accounts. The activity has run since the start of the year, spiked in March, and then stabilized. Victims who launch xeno.exe trigger a loader chain that ends in a Java-based RAT and information stealer.

Related Happenings

Fake Xeno Executor Java RAT and infostealer malware

Malware Activity
H score29 First: 03.08.2026 22:25 Last: 03.08.2026 22:25 Sources 1

How related: The final payload is a Java-based RAT and information stealer malware that combines credential theft with surveillance and remote administration capabilities.

About this happening: The fake Xeno Executor loader chain is dropping a Java-based RAT and information stealer onto devices used by Roblox players, creating a high-risk path to credential...

ClickLock Stealer macOS forced-interaction infostealer activity

Malware Activity
H score27 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...

TikTok and Instagram Reels Vidar social-engineering campaign

Campaign
H score37 First: 10.06.2026 19:00 Last: 10.06.2026 19:00 Sources 1

About this happening: A TikTok and Instagram Reels campaign is using fake free-software tutorials to push Vidar, turning social feeds into a high-reach malware delivery channel. The operati...

JINX-0164 cryptocurrency recruitment-lure campaign

Campaign
H score39 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...

AUDIOFIX and MiniRAT macOS malware activity

Malware Activity
H score34 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...

Timeline

  1. 03.08.2026 22:25 2 articles · 0h ago

    Fake Xeno Executor installers target Roblox players with RAT and infostealer malware

    Initial Disclosure

    Fake Xeno Executor installers targeting Roblox players have circulated since the start of the year, spiking in March before stabilizing; the lure is distributed through gaming forums, Discord communities, and compromised or impersonated accounts, and victims who launch xeno.exe trigger a loader chain that ends in a Java-based RAT and information stealer with browser-data theft, account-token theft, crypto-wallet theft, keylogging, screenshot capture, desktop streaming, webcam access, file transfer, PowerShell execution, and remote shell control.

    Show sources