Roblox fake Xeno Executor installer campaign
Campaign
Summary
Hide ▲
Show ▼
The fake Xeno Executor installer campaign is spreading malware to Roblox players, putting account data, payment details, and remote access at risk. Operators push the lure through gaming forums, Discord communities, and compromised or impersonated accounts. The activity has run since the start of the year, spiked in March, and then stabilized. Victims who launch xeno.exe trigger a loader chain that ends in a Java-based RAT and information stealer.
Related Happenings
Fake Xeno Executor Java RAT and infostealer malware
Malware Activity
H score29
First: 03.08.2026 22:25
Last: 03.08.2026 22:25
Sources 1
How related:
The final payload is a Java-based RAT and information stealer malware that combines credential theft with surveillance and remote administration capabilities.
About this happening:
The fake Xeno Executor loader chain is dropping a Java-based RAT and information stealer onto devices used by Roblox players, creating a high-risk path to credential...
Fake Xeno Executor Java RAT and infostealer malware
Malware ActivityHow related: The final payload is a Java-based RAT and information stealer malware that combines credential theft with surveillance and remote administration capabilities.
About this happening: The fake Xeno Executor loader chain is dropping a Java-based RAT and information stealer onto devices used by Roblox players, creating a high-risk path to credential...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware Activity
H score27
First: 16.07.2026 15:33
Last: 16.07.2026 15:33
Sources 1
About this happening:
ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
ClickLock Stealer macOS forced-interaction infostealer activity
Malware ActivityAbout this happening: ClickLock Stealer is a macOS information-stealing malware that uses a ClickFix-style paste into Terminal and a fake system dialog to coerce users into entering the...
TikTok and Instagram Reels Vidar social-engineering campaign
Campaign
H score37
First: 10.06.2026 19:00
Last: 10.06.2026 19:00
Sources 1
About this happening:
A TikTok and Instagram Reels campaign is using fake free-software tutorials to push Vidar, turning social feeds into a high-reach malware delivery channel. The operati...
TikTok and Instagram Reels Vidar social-engineering campaign
CampaignAbout this happening: A TikTok and Instagram Reels campaign is using fake free-software tutorials to push Vidar, turning social feeds into a high-reach malware delivery channel. The operati...
JINX-0164 cryptocurrency recruitment-lure campaign
Campaign
H score39
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
JINX-0164 cryptocurrency recruitment-lure campaign
CampaignAbout this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...
AUDIOFIX and MiniRAT macOS malware activity
Malware Activity
H score34
First: 28.05.2026 10:54
Last: 28.05.2026 10:54
Sources 1
About this happening:
The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...
AUDIOFIX and MiniRAT macOS malware activity
Malware ActivityAbout this happening: The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...
Timeline
-
03.08.2026 22:25 2 articles · 0h ago
Fake Xeno Executor installers target Roblox players with RAT and infostealer malware
Initial DisclosureFake Xeno Executor installers targeting Roblox players have circulated since the start of the year, spiking in March before stabilizing; the lure is distributed through gaming forums, Discord communities, and compromised or impersonated accounts, and victims who launch xeno.exe trigger a loader chain that ends in a Java-based RAT and information stealer with browser-data theft, account-token theft, crypto-wallet theft, keylogging, screenshot capture, desktop streaming, webcam access, file transfer, PowerShell execution, and remote shell control.
Show sources
- Fake Roblox Xeno script launcher pushes infostealer, RAT malware — www.bleepingcomputer.com — 03.08.2026 22:25
- Fake Roblox Xeno script launcher pushes infostealer, RAT malware — www.bleepingcomputer.com — 03.08.2026 22:25