Date: 08/04/2026
Severity: High
Summary
Threat actors are distributing a fake "undetected" Xeno Roblox script executor through gaming forums and Discord to deliver a multi-stage Java-based stealer and RAT. The malware disguises itself as legitimate Xeno and Windows components, stealing browser cookies, Discord, Roblox and Minecraft accounts, cryptocurrency wallets, and payment data, while also enabling keylogging, webcam access, desktop streaming, PowerShell execution, file manipulation, and full remote control. Previously tracked as Powercat, the malware remains under active development with new command-and-control infrastructure and enhanced capabilities.
Indicators of Compromise (IOC) List
Domains/URLs | https://solthere.net/justacoolkat10 https://solthere.net/api/v1/redeem ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz |
Hash | 4bdaf7792e908f163ebef137854c571d
9930036e8f787674db39094e21413e77
9699bd6a448d0662a1e9e353223263b6
1a462c76efc4e73725b9e95c4a00fddb
7b96170259a376ea79411c5713beb396
2ead73ed62f1c2beb9043ce92e774e0b
0aadd62b535e683a5a2fe31fde546d07
26a94168fa25af0bcb46a18ede50af86
0d03faf1764297c908158da77c8ffcae
d123dbb5c5980bfeb22586197d2cc403
163c8d117ef5a4e4e9c3e92a726af0eb
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "https://solthere.net/justacoolkat10" or url like "https://solthere.net/justacoolkat10" or siteurl like "https://solthere.net/justacoolkat10" or domainname like "https://solthere.net/api/v1/redeem" or url like "https://solthere.net/api/v1/redeem" or siteurl like "https://solthere.net/api/v1/redeem" or domainname like "ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz" or url like "ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz" or siteurl like "ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz" |
Detection Query 2 : | md5hash IN ("9699bd6a448d0662a1e9e353223263b6","4bdaf7792e908f163ebef137854c571d","26a94168fa25af0bcb46a18ede50af86","d123dbb5c5980bfeb22586197d2cc403","0d03faf1764297c908158da77c8ffcae","163c8d117ef5a4e4e9c3e92a726af0eb","9930036e8f787674db39094e21413e77","1a462c76efc4e73725b9e95c4a00fddb","7b96170259a376ea79411c5713beb396","0aadd62b535e683a5a2fe31fde546d07","2ead73ed62f1c2beb9043ce92e774e0b")
|
Reference:
https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor