Fake Roblox Xeno Cheats Deliver Java Stealer Through Discord and Forums

· Original article ↗

Summary

Bitdefender researchers detail a multi-stage Java malware campaign spread as fake Xeno Roblox cheats. The final payload steals accounts and financial data, spies on victims, and enables remote control of infected Windows systems.

Key points

  • Fake “undetected” Xeno cheats promoted on gaming forums and Discord trick users into running a malicious loader.
  • The multi-stage infection uses Java payloads disguised as executables and DLLs, sandbox checks, and a Windows Run-key entry for persistence.
  • The final payload targets browser data, Discord, Roblox and Minecraft accounts, Exodus and other cryptocurrency wallets, and payment-related tokens.
  • Its surveillance and remote-access functions include keylogging, webcam and screen capture, file operations, PowerShell commands, and an interactive shell.
  • Researchers identified new command-and-control infrastructure and self-update functionality; they say the campaign has affected users since early in the year and remains active.
  • Bitdefender recommends avoiding unofficial cheats and executors, alongside endpoint protection, application controls, and multifactor authentication.

Article Details

Attack Vectors
  • Fake versions of the Xeno Roblox script executor were promoted as “undetected” cheats through gaming forums and Discord communities, including through compromised or impersonated accounts.
  • Victims were instructed to run a malicious xeno.exe from a package resembling a legitimate Xeno installation.
  • The loader launched an obfuscated Java stage that contacted a command-and-control server, retrieved another payload, and executed a Java stealer disguised as a Windows DLL.
Defensive Notes
  • Avoid unofficial cheats and executors distributed through untrusted websites, archives, forums, or unsolicited Discord messages.
  • Use updated endpoint protection, reputation-based blocking, application-control policies, multi-factor authentication, and restrictions on software execution.
  • Discuss gaming-related scams with younger users.

Indicators of compromise

TypeIndicatorContext
DOMAINce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a[.]xyzDynamically generated C2 address used by the third-stage stealer.
MD50aadd62b535e683a5a2fe31fde546d07Hash listed for a malicious xeno.exe loader.
MD50d03faf1764297c908158da77c8ffcaeHash listed for a malicious xeno.exe loader.
MD5163c8d117ef5a4e4e9c3e92a726af0ebHash listed for the third-stage JAR placed in GameDVR.
MD51a462c76efc4e73725b9e95c4a00fddbHash listed for an archive containing a fake Xeno installation.
MD526a94168fa25af0bcb46a18ede50af86Hash listed for a malicious xeno.exe loader.
MD52ead73ed62f1c2beb9043ce92e774e0bHash listed for a malicious xeno.exe loader.
MD54bdaf7792e908f163ebef137854c571dHash listed for an archive containing a fake Xeno installation.
MD57b96170259a376ea79411c5713beb396Hash listed for an archive containing a fake Xeno installation.
MD59699bd6a448d0662a1e9e353223263b6Hash listed for an archive containing a fake Xeno installation.
MD59930036e8f787674db39094e21413e77Hash listed for an archive containing a fake Xeno installation.
MD5d123dbb5c5980bfeb22586197d2cc403Hash listed for the malicious decompiler.jar stage.
URLhxxps[:]//solthere[.]net/api/v1/redeemC2 endpoint used to retrieve further payloads.
URLhxxps[:]//solthere[.]net/justacoolkat10C2 endpoint used to register victim machines.

MITRE ATT&CK

T1027 · Obfuscated Files or InformationThe decompiler.exe Java bytecode was obfuscated with Allatori.T1036.005 · Match Legitimate Resource Name or LocationMalware components used Xeno-like files, Windows DLL-like names, and a Microsoft GameDVR directory to appear legitimate.T1036.008 · Masquerade File TypeA Java JAR masqueraded as decompiler.exe, while the third-stage JAR masqueraded as a DLL.T1041 · Exfiltration Over C2 ChannelThe stealer sent collected wallet tokens, account data, and surveillance output to its C2 server.T1056.001 · KeyloggingThe stealer registered Windows keyboard hooks to log keystrokes.T1059.001 · PowerShellThe malware used PowerShell to extract its Java runtime and to execute received commands and an interactive shell.T1105 · Ingress Tool TransferThe infection chain retrieved additional payloads, and the C2 server could send an updated JAR for execution.T1113 · Screen CaptureThe stealer captured screenshots and could stream screenshots to the C2 server every 500 milliseconds.T1125 · Video CaptureThe stealer captured webcam footage through DirectShow-related COM objects.T1204.002 · Malicious FileVictims were instructed to execute a malicious xeno.exe presented as a Roblox cheat.T1497.001 · System ChecksThe malware checked disk size, MAC addresses, registry and WMI artifacts for signs of a virtualized analysis environment.T1518 · Software DiscoveryThe stealer checked installation paths for wallets, development tools, game launchers, VPNs, messaging applications, Roblox, and Minecraft.T1528 · Steal Application Access TokenThe stealer extracted Discord tokens and tokens found in Microsoft Store Token Broker or Cache files.T1539 · Steal Web Session CookieThe stealer collected browser cookies, including cookies associated with Discord, Roblox, and Minecraft accounts.T1547.001 · Registry Run Keys / Startup FolderThe stealer added its JAR execution command to the Windows Run registry key as Display Calibration and enabled the entry.T1620 · Reflective Code LoadingThe second stage loaded a retrieved Java payload with loadClass and invoked its entry point.T1622 · Debugger EvasionThe Java stage checked debugging arguments and stack-trace modules for signs of analysis.

Malware

Vendors

Products

Tools

Industries

Related Articles