Fake Roblox Xeno Cheats Deliver Java Stealer Through Discord and Forums

Summary
Bitdefender researchers detail a multi-stage Java malware campaign spread as fake Xeno Roblox cheats. The final payload steals accounts and financial data, spies on victims, and enables remote control of infected Windows systems.
Key points
- Fake “undetected” Xeno cheats promoted on gaming forums and Discord trick users into running a malicious loader.
- The multi-stage infection uses Java payloads disguised as executables and DLLs, sandbox checks, and a Windows Run-key entry for persistence.
- The final payload targets browser data, Discord, Roblox and Minecraft accounts, Exodus and other cryptocurrency wallets, and payment-related tokens.
- Its surveillance and remote-access functions include keylogging, webcam and screen capture, file operations, PowerShell commands, and an interactive shell.
- Researchers identified new command-and-control infrastructure and self-update functionality; they say the campaign has affected users since early in the year and remains active.
- Bitdefender recommends avoiding unofficial cheats and executors, alongside endpoint protection, application controls, and multifactor authentication.
Article Details
- Attack Vectors
- Fake versions of the Xeno Roblox script executor were promoted as “undetected” cheats through gaming forums and Discord communities, including through compromised or impersonated accounts.
- Victims were instructed to run a malicious xeno.exe from a package resembling a legitimate Xeno installation.
- The loader launched an obfuscated Java stage that contacted a command-and-control server, retrieved another payload, and executed a Java stealer disguised as a Windows DLL.
- Defensive Notes
- Avoid unofficial cheats and executors distributed through untrusted websites, archives, forums, or unsolicited Discord messages.
- Use updated endpoint protection, reputation-based blocking, application-control policies, multi-factor authentication, and restrictions on software execution.
- Discuss gaming-related scams with younger users.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a[.]xyz | Dynamically generated C2 address used by the third-stage stealer. |
| MD5 | 0aadd62b535e683a5a2fe31fde546d07 | Hash listed for a malicious xeno.exe loader. |
| MD5 | 0d03faf1764297c908158da77c8ffcae | Hash listed for a malicious xeno.exe loader. |
| MD5 | 163c8d117ef5a4e4e9c3e92a726af0eb | Hash listed for the third-stage JAR placed in GameDVR. |
| MD5 | 1a462c76efc4e73725b9e95c4a00fddb | Hash listed for an archive containing a fake Xeno installation. |
| MD5 | 26a94168fa25af0bcb46a18ede50af86 | Hash listed for a malicious xeno.exe loader. |
| MD5 | 2ead73ed62f1c2beb9043ce92e774e0b | Hash listed for a malicious xeno.exe loader. |
| MD5 | 4bdaf7792e908f163ebef137854c571d | Hash listed for an archive containing a fake Xeno installation. |
| MD5 | 7b96170259a376ea79411c5713beb396 | Hash listed for an archive containing a fake Xeno installation. |
| MD5 | 9699bd6a448d0662a1e9e353223263b6 | Hash listed for an archive containing a fake Xeno installation. |
| MD5 | 9930036e8f787674db39094e21413e77 | Hash listed for an archive containing a fake Xeno installation. |
| MD5 | d123dbb5c5980bfeb22586197d2cc403 | Hash listed for the malicious decompiler.jar stage. |
| URL | hxxps[:]//solthere[.]net/api/v1/redeem | C2 endpoint used to retrieve further payloads. |
| URL | hxxps[:]//solthere[.]net/justacoolkat10 | C2 endpoint used to register victim machines. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationThe decompiler.exe Java bytecode was obfuscated with Allatori.T1036.005 · Match Legitimate Resource Name or LocationMalware components used Xeno-like files, Windows DLL-like names, and a Microsoft GameDVR directory to appear legitimate.T1036.008 · Masquerade File TypeA Java JAR masqueraded as decompiler.exe, while the third-stage JAR masqueraded as a DLL.T1041 · Exfiltration Over C2 ChannelThe stealer sent collected wallet tokens, account data, and surveillance output to its C2 server.T1056.001 · KeyloggingThe stealer registered Windows keyboard hooks to log keystrokes.T1059.001 · PowerShellThe malware used PowerShell to extract its Java runtime and to execute received commands and an interactive shell.T1105 · Ingress Tool TransferThe infection chain retrieved additional payloads, and the C2 server could send an updated JAR for execution.T1113 · Screen CaptureThe stealer captured screenshots and could stream screenshots to the C2 server every 500 milliseconds.T1125 · Video CaptureThe stealer captured webcam footage through DirectShow-related COM objects.T1204.002 · Malicious FileVictims were instructed to execute a malicious xeno.exe presented as a Roblox cheat.T1497.001 · System ChecksThe malware checked disk size, MAC addresses, registry and WMI artifacts for signs of a virtualized analysis environment.T1518 · Software DiscoveryThe stealer checked installation paths for wallets, development tools, game launchers, VPNs, messaging applications, Roblox, and Minecraft.T1528 · Steal Application Access TokenThe stealer extracted Discord tokens and tokens found in Microsoft Store Token Broker or Cache files.T1539 · Steal Web Session CookieThe stealer collected browser cookies, including cookies associated with Discord, Roblox, and Minecraft accounts.T1547.001 · Registry Run Keys / Startup FolderThe stealer added its JAR execution command to the Windows Run registry key as Display Calibration and enabled the entry.T1620 · Reflective Code LoadingThe second stage loaded a retrieved Java payload with loadClass and invoked its entry point.T1622 · Debugger EvasionThe Java stage checked debugging arguments and stack-trace modules for signs of analysis.
Malware
Vendors
Products
DiscordFake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and ForumsExodusis enabled, it starts two threads responsible for collecting and sending crypto wallet data stolen from Exodus wallets. It then calls the function that creates a WebSocket connection to the C2 server.Microsoft StoreRoblox cookie parsingFig. 30. Minecraft cookie parsingFinally, the malware can extract tokens from Microsoft Store logins with the goal of stealing stored payment information. It locates .tbres files in the TokenMinecraftThe final payload goes far beyond conventional credential theft. It can steal browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency-wallet data and payment information.RobloxFake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and ForumsWindowsJava infection chain built to stay hidden in plain sight. Its components imitate real Xeno files, use Windows-style names and hide inside trusted-looking directories, which includes a folder associated with XboxXenoFake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
Tools
AllatoriJAR file masquerading as a Windows executable. Its Java bytecode is obfuscated with the demo version of Allatori, a legitimate commercial obfuscation tool that the malware authors have abused. This can be at leastCMSTPFig. 13. Logging functionAfter that, the malware attempts to move execution to a CMSTP process with elevated privileges. If privilege escalation succeeds, the low-privilege javaw.exe process terminates. If privilegePowerShellone can also record keystrokes, access the webcam, stream the victim’s desktop, manipulate files, run PowerShell commands and give attackers interactive control of the infected computer.