Protect.Computer
NEWS

Fake Roblox Xeno Launcher Delivers Infostealer and RAT Malware

· 1 min read · Digital scams Malicious byte
Fake Roblox Xeno Launcher Delivers Infostealer and RAT Malware

Roblox players hunting for unofficial “script executors” — tools that let players run custom code or cheats in the game — have been targeted by a malware campaign since the beginning of 2026. Cybersecurity firm Bitdefender found that attackers are distributing fake versions of Xeno Executor, one of the most popular of these utilities, through Discord servers, gaming forums, YouTube tutorials, and compromised accounts.

Because Roblox periodically blocks existing executor versions, players routinely go looking for new releases — a fact the attackers exploit by flooding unofficial channels with malicious installers that look convincing. Installing the fake Xeno Executor drops two payloads: an infostealer that harvests saved browser credentials, cookies, and cryptocurrency wallet files, and a remote access trojan (RAT) that gives the attacker persistent, hidden control over the victim’s device. Bitdefender observed a sharp spike in infections in March 2026. The campaign targets Windows users specifically and relies almost entirely on social engineering — there is no software vulnerability being exploited; the victim simply runs what they believe is a game utility.

How to check if you’re affected

Affected devices include any Windows computer where a Xeno Executor installer was downloaded from Discord, a gaming forum, a YouTube tutorial link, or any website other than the tool’s verified official repository. If you or someone in your household installed Xeno Executor recently, run a full antivirus scan with an up-to-date engine and check your saved browser passwords for unexpected logins. If the device shows signs of compromise, change passwords for all important accounts — especially email, gaming, and any accounts with stored payment details — from a clean device.

Sources

Related reading