Roblox Malware Streams Victims’ Desktops and Captures Webcam Footage

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

A malicious Roblox cheat campaign is turning a familiar gaming shortcut into a serious privacy threat.

Players seeking an “undetected” Xeno script executor are being lured through gaming forums and Discord communities into downloading files that appear to offer game automation.

Instead, the package starts a hidden, multi-stage infection that can give criminals control of the computer.

The operation is especially concerning because Roblox cheats often attract younger users who may use shared family devices.

Once installed, the malware can target gaming accounts, browser data, payment information, private messages, and cryptocurrency wallets, creating risks that extend well beyond a lost game account.

Bitdefender researchers identified the campaign while tracking fake Xeno packages promoted through gaming channels.

Bitdefender said in a report shared with Cyber Security News (CSN) that the researchers found activity affecting users since the beginning of the year, with infections rising sharply during the second half of March before settling into a steady rate.

Java stealer killchain (Source – Bitdefender)

The investigation links the operation to malware previously documented as Powercat, while newly observed infrastructure and expanded functions suggest that its operators are continuing to develop it.

Roblox Malware

The fake cheat uses familiar-looking folders, copied game-related scripts, and Windows-style names to make the download appear legitimate.

It first checks whether the device is being analyzed in a virtual environment, helping attackers avoid security researchers and automated detection systems before delivering the final payload.

The final malware can capture screenshots, log keyboard and mouse activity, access a webcam, and stream the victim’s desktop in near real time.

Its display-streaming feature captures images every 500 milliseconds and sends them to the attackers, effectively creating a live view of the infected screen.

That level of access can expose private chats, documents, passwords entered into websites, and images visible on screen.

Mimicking a Xeno installation (Source – Bitdefender)

Similar threats have shown how gaming lures can combine account theft with remote monitoring, as seen in this report on malware targeting game cheats, where attackers used fake tools to reach gamers.

The malware can also receive commands, transfer files, run PowerShell commands, and open an interactive remote shell.

This means a compromise may continue after initial data theft, allowing criminals to alter files, deploy more malware, or use the device in other criminal activity.

The infection begins when a victim downloads an archive or self-extracting package advertised as a cheat.

The staged process then retrieves additional components from attacker-controlled servers, disguising Java-based files as ordinary Windows programs and libraries to reduce suspicion.

The malware searches for browser cookies and saved data from Discord, Roblox, Minecraft, and several browsers.

It also checks for cryptocurrency wallets, messaging applications, game launchers, VPN software, and development tools, enabling attackers to prioritize systems that may contain valuable accounts or financial information.

Discord is a central part of the distribution lure, but it is also widely abused for malicious delivery and control.

DirectShow-related GUIDs (Source – Bitdefender)

Readers can see the broader pattern in CSN’s examination of modern malware abusing Discord, which explains how trusted community platforms can be misused to spread dangerous files.

Users should avoid unofficial executors, cheats, and game modifications shared through forums, archives, untrusted websites, or unsolicited Discord messages.

Updated endpoint protection, application controls, multi-factor authentication, and reputation-based blocking can reduce exposure, while parents should discuss common gaming scams with younger players.

Anyone who executed a suspicious game tool should change passwords from a clean device, revoke active sessions, and review financial accounts for unusual activity.

The combination of screen surveillance and account theft also mirrors risks described in a recent screen and webcam malware investigation, where attackers used remote access to collect sensitive data.

Indicators of Compromise (IoCs):-

Type Indicator Description
MD5 4bdaf7792e908f163ebef137854c571d Archive containing fake Xeno installation 
MD5 9930036e8f787674db39094e21413e77 Archive containing fake Xeno installation 
MD5 9699bd6a448d0662a1e9e353223263b6 Archive containing fake Xeno installation 
MD5 1a462c76efc4e73725b9e95c4a00fddb Archive containing fake Xeno installation 
MD5 7b96170259a376ea79411c5713beb396 Archive containing fake Xeno installation 
MD5 2ead73ed62f1c2beb9043ce92e774e0b Malicious loader 
MD5 0aadd62b535e683a5a2fe31fde546d07 Malicious loader 
MD5 26a94168fa25af0bcb46a18ede50af86 Malicious loader 
MD5 0d03faf1764297c908158da77c8ffcae Malicious loader 
MD5 d123dbb5c5980bfeb22586197d2cc403 Java archive payload 
MD5 163c8d117ef5a4e4e9c3e92a726af0eb Third-stage Java archive from GameDVR directory 
URL hxxps://solthere[.]net/justacoolkat10 Victim registration endpoint 
URL hxxps://solthere[.]net/api/v1/redeem Additional payload retrieval endpoint 
Domain ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a.xyz Dynamically generated command-and-control address 
File name RbxAnalytics.png Junk-data file used to support the fake Xeno installation appearance 
File name xeno.exe Malicious first-stage loader masquerading as the Xeno executable 
File name instance.exe Archive used to extract the Java Runtime Environment 
File name XenoIcon.jpg File containing keys used to validate execution with the command-and-control server 
File name decompiler.exe Java archive disguised as a Windows executable 
File name -ntcache Local execution-progress log file 
File name SquirrelInteractive.bin File used to store logged Exodus wallet-related buffers 
Registry value DisplayCalibration Run-key persistence entry used to launch the Java archive 

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Building Resilience Against Phishing & Malware and Analyze it in a safe environment – Power your SOC with ANY.RUN