Fake Xeno is a multi-stage Trojan that combines information-stealing capabilities with Remote Access Trojan (RAT) functionality. It disguises itself as the “Xeno” Roblox script executor, a cheat tool promoted to players through gaming forums and Discord communities. Once executed, the malware operates in the background while stealing sensitive information and providing its operator with remote access to the infected computer.
The infection consists of three stages. The first is an executable named “xeno.exe”, which extracts a bundled Java Runtime Environment and launches the next component. The second stage is a heavily obfuscated Java archive containing anti-analysis mechanisms. The final payload is stored inside a directory designed to resemble the Xbox Game Bar GameDVR folder and is disguised as a Windows DLL file.
Fake Xeno communicates with its command-and-control infrastructure through an encrypted WebSocket connection. Once active, it provides extensive surveillance capabilities. The malware can record keyboard and mouse activity, capture screenshots approximately every half-second, stream the desktop in near real time, and access the webcam.
Attackers can also open an interactive PowerShell shell or command prompt, execute commands, and browse files on the compromised system. Fake Xeno supports downloading files from the computer as well as uploading additional files to it. A built-in privilege escalation mechanism allows its operator to request elevated permissions when necessary.
The information-stealing component targets numerous applications and account types. It extracts browser cookies from Chrome, Edge, Brave, Opera, Opera GX, and Vivaldi. It can steal Discord tokens, Roblox and Minecraft session credentials, and tokens associated with several third-party Minecraft launchers.
Cryptocurrency wallets are another target. Fake Xeno searches for data associated with Exodus, Atomic, Cake Wallet, SafePal, TronWallet, and Monero Wallet. It also targets gaming platforms including Steam, Epic Games, Battle.net, Riot Client, and Rockstar Games Launcher, along with several VPN applications and developer tools. Microsoft Store payment tokens stored in local cache files are also among the information targeted by the malware.
Fake Xeno establishes persistence by creating a Windows Registry Run entry named “Display Calibration”. Its files are placed in user-writable directories with names intended to resemble legitimate Windows and Xbox Game Bar locations. The malware also performs checks for debuggers, developer environments, virtual machines, disk characteristics, and MAC addresses to identify analysis environments.
How is Fake Xeno distributed and how can infections be avoided?
Fake Xeno has been distributed primarily through gaming forums and Discord communities. The campaign promotes the malware as a free and “undetected” Roblox script executor, targeting users searching for cheat tools and ways to bypass anti-cheat systems. The campaign has been active since at least early 2026, with increased activity observed beginning in March.
The malicious package is distributed as a self-extracting archive designed to resemble a legitimate Xeno installer. Download links can appear directly in Discord servers and gaming forum discussions, where the surrounding context may make the file seem credible to players searching for Roblox-related tools. Running the fake installer initiates the multi-stage infection process.
Users should therefore be particularly cautious with script executors, game cheats, modifications, anti-cheat bypasses, and similar tools obtained through unofficial communities. Applications should be downloaded from official developer websites or verified distribution platforms rather than links posted by unknown users in Discord channels or gaming forums.
Unexpected executables and archives should not be opened simply because they use the name of a known tool. A file presented as Xeno can instead contain Fake Xeno, and its malicious activity may occur without obvious signs after execution.
Keeping Windows and installed applications updated and using reputable security software can provide additional protection. Suspicious links and advertisements should be avoided, and notification permissions should not be granted to unfamiliar websites.
Remove Fake Xeno trojan
If Fake Xeno has already been executed, the affected system should be treated as compromised because the malware can steal credentials, session tokens, cryptocurrency wallet information, and other sensitive data while providing attackers with remote control. The computer should be disconnected from networks where appropriate and scanned with legitimate security software to remove the infection.
Credentials potentially exposed on the compromised computer should also be changed using a clean device. Sessions associated with affected accounts should be revoked where possible, particularly because Fake Xeno specifically targets Discord tokens, browser data, Roblox and Minecraft sessions, cryptocurrency wallets, and gaming accounts.
Site Disclaimer
2-remove-virus.com is not sponsored, owned, affiliated, or linked to malware developers or distributors that are referenced in this article. The article does not promote or endorse any type of malware. We aim at providing useful information that will help computer users to detect and eliminate the unwanted malicious programs from their computers. This can be done manually by following the instructions presented in the article or automatically by implementing the suggested anti-malware tools.
The article is only meant to be used for educational purposes. If you follow the instructions given in the article, you agree to be contracted by the disclaimer. We do not guarantee that the artcile will present you with a solution that removes the malign threats completely. Malware changes constantly, which is why, in some cases, it may be difficult to clean the computer fully by using only the manual removal instructions.
