Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums

    Date: 08/04/2026

    Severity: High

    Summary

    Threat actors are distributing a fake "undetected" Xeno Roblox script executor through gaming forums and Discord to deliver a multi-stage Java-based stealer and RAT. The malware disguises itself as legitimate Xeno and Windows components, stealing browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency wallets, and payment data, while also enabling keylogging, webcam access, desktop streaming, PowerShell execution, file manipulation, and full remote control. Previously tracked as Powercat, the malware remains under active development with new command-and-control infrastructure and enhanced capabilities. 

    Indicators of Compromise (IOC) List

    Domains/URLs

    https://solthere.net/justacoolkat10

    https://solthere.net/api/v1/redeem

    ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz

    Hash

    4bdaf7792e908f163ebef137854c571d

    9930036e8f787674db39094e21413e77

    9699bd6a448d0662a1e9e353223263b6

    1a462c76efc4e73725b9e95c4a00fddb

    7b96170259a376ea79411c5713beb396

    2ead73ed62f1c2beb9043ce92e774e0b

    0aadd62b535e683a5a2fe31fde546d07

    26a94168fa25af0bcb46a18ede50af86

    0d03faf1764297c908158da77c8ffcae

    d123dbb5c5980bfeb22586197d2cc403

    163c8d117ef5a4e4e9c3e92a726af0eb

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "https://solthere.net/justacoolkat10" or url like "https://solthere.net/justacoolkat10" or siteurl like "https://solthere.net/justacoolkat10" or domainname like "https://solthere.net/api/v1/redeem" or url like "https://solthere.net/api/v1/redeem" or siteurl like "https://solthere.net/api/v1/redeem" or domainname like "ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz" or url like "ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz" or siteurl like "ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz"

    Detection Query 2 :

    md5hash IN ("9699bd6a448d0662a1e9e353223263b6","4bdaf7792e908f163ebef137854c571d","26a94168fa25af0bcb46a18ede50af86","d123dbb5c5980bfeb22586197d2cc403","0d03faf1764297c908158da77c8ffcae","163c8d117ef5a4e4e9c3e92a726af0eb","9930036e8f787674db39094e21413e77","1a462c76efc4e73725b9e95c4a00fddb","7b96170259a376ea79411c5713beb396","0aadd62b535e683a5a2fe31fde546d07","2ead73ed62f1c2beb9043ce92e774e0b")

    Reference:    

    https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor                                


    Tags

    MalwareGamingDiscordStealerRATcryptocurrencyKeyloggerPowerShell AttackFinancial ServicesRoblox

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags