Fake Xeno Executor downloads are infecting Roblox players with infostealer and remote-access malware

Attackers are luring Roblox players into downloading fake Xeno Executor installers that secretly infect their computers with malware. Bitdefender says the campaign has run since early 2026 and spreads through gaming forums, Discord communities, and compromised or impersonated accounts. The fake launcher drops a Java-based remote-access trojan and information stealer that can grab browser cookies, Discord and Roblox data, Microsoft Store tokens, payment information, crypto-wallet data, screenshots, keystrokes, and webcam access.
Why it matters: This affects consumers directly, especially younger gamers who may be tempted by unofficial Roblox tools advertised as “undetected.” Anyone who ran a fake Xeno installer should treat their device and accounts as compromised, remove the malware, change passwords, and be cautious of third-party Roblox utilities shared through Discord or forums.

Sources

Fake Roblox Xeno script launcher pushes infostealer, RAT malware
Bill Toulas 2026.08.03 100% relevant
This article establishes a distinct malware campaign centered on fake Xeno Executor installers for Roblox, with specific delivery channels, payload behavior, and victim community.
← Back to all stories