Cyber Security News

Roblox Malware Streams Victims’ Desktops and Captures Webcam Footage

A malicious Roblox cheat campaign is turning a familiar gaming shortcut into a serious privacy threat.

Players seeking an “undetected” Xeno script executor are being lured through gaming forums and Discord communities into downloading files that appear to offer game automation.

Instead, the package starts a hidden, multi-stage infection that can give criminals control of the computer.

The operation is especially concerning because Roblox cheats often attract younger users who may use shared family devices.

Once installed, the malware can target gaming accounts, browser data, payment information, private messages, and cryptocurrency wallets, creating risks that extend well beyond a lost game account.

Bitdefender researchers identified the campaign while tracking fake Xeno packages promoted through gaming channels.

Bitdefender said in a report shared with Cyber Security News (CSN) that the researchers found activity affecting users since the beginning of the year, with infections rising sharply during the second half of March before settling into a steady rate.

Java stealer killchain (Source – Bitdefender)

The investigation links the operation to malware previously documented as Powercat, while newly observed infrastructure and expanded functions suggest that its operators are continuing to develop it.

Roblox Malware

The fake cheat uses familiar-looking folders, copied game-related scripts, and Windows-style names to make the download appear legitimate.

It first checks whether the device is being analyzed in a virtual environment, helping attackers avoid security researchers and automated detection systems before delivering the final payload.

The final malware can capture screenshots, log keyboard and mouse activity, access a webcam, and stream the victim’s desktop in near real time.

Its display-streaming feature captures images every 500 milliseconds and sends them to the attackers, effectively creating a live view of the infected screen.

That level of access can expose private chats, documents, passwords entered into websites, and images visible on screen.

Mimicking a Xeno installation (Source – Bitdefender)

Similar threats have shown how gaming lures can combine account theft with remote monitoring, as seen in this report on malware targeting game cheats, where attackers used fake tools to reach gamers.

The malware can also receive commands, transfer files, run PowerShell commands, and open an interactive remote shell.

This means a compromise may continue after initial data theft, allowing criminals to alter files, deploy more malware, or use the device in other criminal activity.

From Cheat Download to Takeover

The infection begins when a victim downloads an archive or self-extracting package advertised as a cheat.

The staged process then retrieves additional components from attacker-controlled servers, disguising Java-based files as ordinary Windows programs and libraries to reduce suspicion.

The malware searches for browser cookies and saved data from Discord, Roblox, Minecraft, and several browsers.

It also checks for cryptocurrency wallets, messaging applications, game launchers, VPN software, and development tools, enabling attackers to prioritize systems that may contain valuable accounts or financial information.

Discord is a central part of the distribution lure, but it is also widely abused for malicious delivery and control.

DirectShow-related GUIDs (Source – Bitdefender)

Readers can see the broader pattern in CSN’s examination of modern malware abusing Discord, which explains how trusted community platforms can be misused to spread dangerous files.

Users should avoid unofficial executors, cheats, and game modifications shared through forums, archives, untrusted websites, or unsolicited Discord messages.

Updated endpoint protection, application controls, multi-factor authentication, and reputation-based blocking can reduce exposure, while parents should discuss common gaming scams with younger players.

Anyone who executed a suspicious game tool should change passwords from a clean device, revoke active sessions, and review financial accounts for unusual activity.

The combination of screen surveillance and account theft also mirrors risks described in a recent screen and webcam malware investigation, where attackers used remote access to collect sensitive data.

Indicators of Compromise (IoCs):-

TypeIndicatorDescription
MD54bdaf7792e908f163ebef137854c571dArchive containing fake Xeno installation
MD59930036e8f787674db39094e21413e77Archive containing fake Xeno installation
MD59699bd6a448d0662a1e9e353223263b6Archive containing fake Xeno installation
MD51a462c76efc4e73725b9e95c4a00fddbArchive containing fake Xeno installation
MD57b96170259a376ea79411c5713beb396Archive containing fake Xeno installation
MD52ead73ed62f1c2beb9043ce92e774e0bMalicious loader
MD50aadd62b535e683a5a2fe31fde546d07Malicious loader
MD526a94168fa25af0bcb46a18ede50af86Malicious loader
MD50d03faf1764297c908158da77c8ffcaeMalicious loader
MD5d123dbb5c5980bfeb22586197d2cc403Java archive payload
MD5163c8d117ef5a4e4e9c3e92a726af0ebThird-stage Java archive from GameDVR directory
URLhxxps://solthere[.]net/justacoolkat10Victim registration endpoint
URLhxxps://solthere[.]net/api/v1/redeemAdditional payload retrieval endpoint
Domaince953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyzDynamically generated command-and-control address
File nameRbxAnalytics.pngJunk-data file used to support the fake Xeno installation appearance
File namexeno.exeMalicious first-stage loader masquerading as the Xeno executable
File nameinstance.exeArchive used to extract the Java Runtime Environment
File nameXenoIcon.jpgFile containing keys used to validate execution with the command-and-control server
File namedecompiler.exeJava archive disguised as a Windows executable
File name-ntcacheLocal execution-progress log file
File nameSquirrelInteractive.binFile used to store logged Exodus wallet-related buffers
Registry valueDisplayCalibrationRun-key persistence entry used to launch the Java archive

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Building Resilience Against Phishing & Malware and Analyze it in a safe environment – Power your SOC with ANY.RUN

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago