Home / Technology / Roblox Malware: 'Invisible' Xeno Executor Hides RAT
Roblox Malware: 'Invisible' Xeno Executor Hides RAT
4 Aug
Summary
- Fake 'undetected' Xeno Executor mod spreads Java-based RAT and infostealer.
- Malware steals browser data, account tokens, payment info, and crypto wallets.
- Campaign peaked in March 2026 and remains active against millions of Roblox players.

Cybercriminals are actively targeting Roblox players with a malicious "undetected" Xeno Executor mod, which functions as a gateway for a potent Remote Access Trojan (RAT) and an information stealer. This fake utility, promoted across gaming forums and Discord, deceives players into downloading malware that infiltrates their systems. The infection chain culminates in a Java-based RAT capable of stealing a wide array of sensitive information. This includes browser data such as passwords and cookies from popular browsers, alongside account tokens for services like Discord, Roblox, and Minecraft. Additionally, it targets payment information and cryptocurrency wallets, with a specific focus on the Exodus Wallet.
The malware also equips attackers with significant surveillance capabilities. They can log keystrokes, monitor mouse movements, capture screenshots, stream desktop activity, and access webcams. The RAT also grants extensive remote control, allowing for file uploads and downloads, and PowerShell command execution. This campaign began earlier in the year and peaked in March 2026. It has since stabilized but continues to pose a significant threat to the 82 million active players on the Roblox platform.