Campaign active since early 2026, targeting gamers including minors, previously tracked as Powercat.
- Entry point is %LOCALAPPDATA%\Xeno\workspace\cache\xeno.exe, a fake loader that extracts a bundled JRE to %LOCALAPPDATA%\Java\jre\bin\javaw.exe, reads keys from XenoIcon.jpg, then executes decompiler.exe (a JAR obfuscated with Allatori). Stage 2 phones home to hxxps://solthere[.]net/api/v1/redeem with an AES+Base64-encrypted key to pull the next payload.
- Stage 3 drops into %LOCALAPPDATA%\Microsoft\GameDVR under a fake Windows DLL name and persists via HKCU\Software\Microsoft\Windows\CurrentVersion\Run as "Display Calibration". It attempts CMSTP UAC bypass for elevation and generates its C2 URI dynamically: ce953a0eb08246617b7f849486c4b26a7af37e9d2e8f0e13b3ae1bf0da8a70a[.]xyz.
- Capabilities go well beyond credential theft: keylogging, 500ms desktop streaming, webcam capture via DirectShow COM objects, interactive PowerShell shell, and Exodus wallet tampering by injecting JS into app.asar and logging runtime data to SquirrelInteractive.bin.
Hunt for javaw.exe spawned from %LOCALAPPDATA%, "Display Calibration" Run key entries, -ntcache log files in user home, and SquirrelInteractive.bin. Full IOC list with MD5 hashes in the Bitdefender report.
A malware campaign disguised as an “undetected” version of the Xeno Roblox script executor is directly affecting players
www.bitdefender.com