What's Happening?
A new malware campaign is targeting players of popular games like Roblox and Minecraft by disguising itself as an 'undetected' version of the Xeno Roblox script executor. Promoted through gaming forums and Discord communities, the malware launches a multi-stage
Java infection chain that mimics legitimate files and directories. The final payload is a sophisticated stealer and remote access trojan capable of stealing browser cookies, Discord, Roblox, and Minecraft accounts, as well as cryptocurrency-wallet data and payment information. The malware can also record keystrokes, access webcams, stream desktops, manipulate files, and execute commands, giving attackers interactive control over infected computers. This campaign, previously documented as Powercat, remains under active development with newly identified command-and-control infrastructure and expanded functionality.
Why It's Important?
The significance of this malware campaign lies in its potential impact on privacy and financial security. By targeting popular gaming platforms, the malware exploits the habits of gamers who frequently exchange mods and scripts, making them vulnerable to such attacks. The ability to steal sensitive information like account credentials, cryptocurrency-wallet data, and payment tokens poses a significant risk of financial loss and identity theft. Additionally, the malware's surveillance capabilities, including keylogging and webcam access, threaten user privacy. The campaign's continued development and active status suggest an ongoing threat to users, particularly children and teenagers who may be more susceptible to downloading fake cheats.











