-
Threat actors are circulating a fake Xeno Roblox executor that can deliver infostealing malware. It’s capable of spying on users via screenshots, cameras, keylogging techniques and real-time desktop screen sharing.
-
The malware secretly obtains passwords, logging cookies, cryptocurrency wallet information and accounts of game users.
-
The campaign has been active since early 2026 and appears to be an evolving version of the Powercat malware operation.

Roblox players looking for an “undetected” version of the Xeno Executor are being targeted by a malware campaign, Bitdefender warns.
Xeno helps several Roblox players in running scripts and automating different actions. Even though Roblox has termed these unofficial products illegal, many still use them. Malicious actors are taking advantage of that demand to distribute malware masquerading as a fully functional executor.
How does this campaign spread? It’s currently circulating on gaming forums, Discord communities and platforms where gamers share unofficial software. The malware is touted as a version capable of bypassing Roblox’s anti-cheat measures.
Instead, downloading it kickstarts a multi-step infection. Bitdefender found that the malware tries to look like a normal Xeno installation. Later components use names that resemble Windows files.
They also hide in trusted-looking folders and create ways to stay on the computer. That helps the malware remain unnoticed after the original file is opened.
The Attack Goes far Beyond Stolen Passwords
The final payload combines two dangerous roles. It acts as an infostealer, scavenging through the victim’s machine for any information that is useful. Also, it basically lets hackers take over your device from wherever they are.
It also sweeps up logins and cookies across a bunch of different browsers, not just the big names like Chrome and Edge but also Opera, Brave, and Vivaldi. So yeah, pretty much covers all the bases.
And it also tries to extract information from Roblox itself as well as Discord and Minecraft accounts. One of its main targets is crypto wallets, particularly Exodus Wallet. Payment information and Microsoft Store tokens can also be exposed.
The targeting of gaming and sports communities for data theft is not limited to malware campaigns, hackers have recently claimed to have leaked sensitive personal information of players from the Asian Football Confederation, including passport details, home addresses, and medical records.
Stealing account data isn’t the only threat this malware poses; it lets the attacker capture your screenshot and log your keystrokes too. They can track mouse activity and stream the victim’s desktop. The malware can also access the webcam.
It gives attackers tools to upload and download files, run PowerShell commands and open a command console. In practical terms, that can turn a stolen gaming account into a full PC takeover.
Powercat Connection Points to an Ongoing Campaign
The activity is not appearing out of nowhere. Earlier in March 2026, ThreatLocker discovered a malware operation called Powercat. The researchers found that the malware disguises as cheats and game utilities. And it doesn’t just target Roblox, but also Minecraft, Grand Theft Auto V, Discord, and Telegram users.
According to the study, Powercat can also record screens, webcam feeds, keystrokes and mouse movements. Its goal is to obtain browser sessions, Discord tokens, gaming accounts, and cryptocurrency wallets credentials.
Bitdefender has now linked the newer activity to malware previously tracked as Powercat. Researchers say they’ve seen new command-and-control infrastructure popping up, plus extra features. It looks like whoever’s behind this is still building it out.
The campaign started ramping up earlier this year and really took off in March. Activity later settled but remained active. There is no reliable public figure for the number of victims.
Children Face a Particular Risk
This campaign is pretty troubling, especially since Roblox’s user base is mostly young players.
Kids and teens are the ones most likely to search for cheats, scripts, mods, and other unofficial tools. Some of them won’t think twice about downloading something from a Discord server or a gaming forum.
The danger becomes greater on family computers. A single infected machine may contain saved passwords, payment information, private messages and accounts belonging to several people. Webcam and screen access also creates a serious privacy risk. An attacker may see far more than the victim’s Roblox activity.
ThreatLocker previously warned that the ability to identify users by age, combined with webcam and screen capture features, could expose younger users to further abuse.
Fake Executors Remain an Easy Lure
The campaign shows why unofficial game tools remain attractive targets for cybercriminals. Players want an advantage. Attackers offer a tool that promises exactly that. The victim then runs the program voluntarily, often giving the malware the access it needs.
The same pattern has appeared in other fake executor and cheat campaigns. Security researchers have repeatedly found malicious files hiding behind popular gaming tools.
Online reports also show confusion around legitimate and fake Xeno downloads. So, it’s even more difficult for users to tell if what they got is the real version or a fake.
How Players Can Stay Safe
The simplest defense is to avoid unofficial Roblox executors, cheats and scripts. Players should not install files sent through random Discord messages or unknown gaming sites. They should also avoid disabling security software just because a download claims antivirus tools are producing a “false positive.”
Security software should remain updated. Organizations can also use application controls that block unknown programs from running. Multi-factor authentication adds another layer of protection for Roblox, Discord, email and financial accounts.
Parents should also explain the risk to younger players. A free cheat is not worth losing an account, exposing private data or handing an attacker control of the family computer. The biggest warning is simple: a tool promising to beat Roblox’s defenses may instead be designed to beat yours.