This Fake Roblox Cheat Can Watch Your Kid Through the Webcam

A fake Roblox cheat tool is spreading spyware that can steal passwords, private conversations, cryptocurrency, webcam footage, and other sensitive personal information.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

If an increase in viruses and rising concerns about inappropriate content weren’t enough, Roblox is under fire yet again — this time for opening the door for privacy-invasive spyware.[1]

It masquerades as an "undetected" version of the Xeno Roblox cheat tool. Once you trust the suspicious file and install the malware, it not only sees your screen, hears everything you type, and watches you through your own webcam — it also enables the attacker to execute remote commands on your system.

Here’s a detailed breakdown of how this new attack works and what you can do to stay safe on Roblox.

In this article
How the Roblox spyware infects your system
What the malware can do
What can you do to protect yourself
Bottom line

How the Roblox spyware infects your system

According to Bitdefender’s security report, the attack starts when the victim downloads an archive file that looks exactly like a real Xeno installation.

Attackers are sharing these suspicious files on Discord and other gaming forums, advertising them as an "undetected" version of a Roblox cheat tool.

The folder layout, along with some genuine leftover files from the real tool, makes it convincing enough at first glance.

This malware was previously documented by ThreatLocker under the name Powercat, and the new Bitdefender research has identified a new C2 infrastructure, indicating that it’s still under active development.

Here’s how the attack works:

Stage 1

The victim is instructed to run the main file, Xeno.exe. However, this isn’t the real Xeno cheat program but actually the first stage of the malware.

When Xeno.exe runs, it first checks whether Java is installed on the system, since both stage two and stage three are Java programs and require the Java Runtime Environment (JRE) to run.

If Java is missing, it extracts a JRE from a file called instance.exe using a hidden PowerShell command. It then reads hidden keys stored in the XenoIcon.jpg file.

This key serves as a secret authentication code that allows the malware to execute the next stages.

Stage 2

The malware then launches stage two by starting javaw.exe and instructing it to run a JAR file disguised as decompiler.exe, making it appear like a normal Windows program.

The attacker also scrambles the program’s internal code using Allatori, a popular Java obfuscation tool. When the program starts, it even prints a small text banner revealing that it was built using Allatori.

The second stage then performs several preliminary checks before proceeding. It checks whether it’s currently being debugged by a security researcher and whether it’s running inside a sandbox.

After checking the environment, the results are sent to the attacker’s command-and-control (C2) server. This is also the stage where the malware proves its legitimacy using the secret key extracted from the XenoIcon.jpg file.

If the key is validated successfully, the attacker’s C2 server sends the next stage of the malware, which is then saved inside a folder associated with Xbox Game Bar (a legitimate Windows feature) so that it blends in with genuine system files.

Stage 3

The downloaded spyware is disguised as a legitimate Windows system DLL file. When launched, it first checks for debugging and sandbox environments, just like the previous stage.

However, this time, if it detects either one, it doesn’t report back to the C2 server but instead shuts itself down immediately.

  1. After a successful check, the malware writes a log file so that the attacker can track its progress later.
  2. It then attempts to escalate its privileges on the user’s system using a legitimate Windows tool called CMSTP. If this fails, it continues running with regular user privileges instead.
  3. The malware uses your IP address to determine your approximate location and helps the attacker generate a unique ID for your system.
  4. It also adds itself to the list of auto-start programs in Windows so that it launches automatically every time you start your computer.
  5. Next, it establishes a live connection to the attacker’s command-and-control (C2) server, allowing the attacker to send commands that the malware executes in real time.
  6. The C2 server can also push updated versions of the JAR file itself, which the malware can save under a new disguised filename. This shows that the malware is actively evolving.

What the malware can do

If successful, the attacker could gain near-complete control over your system. They can access your webcam, record your screen, log every key you press, steal cryptocurrency wallet credentials and payment information, and exfiltrate files from your device.

Speaking of logging keystrokes, this means the malware could harvest virtually any information you type on your system. This includes personally identifiable information such as email addresses, phone numbers, financial account credentials, passwords, and more.

These details could then be used for social engineering scams, including phishing attacks, which could ultimately lead to identity theft or financial fraud.

Bitdefender’s report also describes a more alarming technique that the malware uses to steal cryptocurrency wallet credentials.

The malware can actively modify the Exodus Wallet application's own files, including its JavaScript code, to disable its sandboxing and log wallet activity to a separate file, which is then exfiltrated.

What can you do to protect yourself

Here are some steps you can take to stay safe from this intrusive spyware.

  1. Avoid unofficial cheats: The Xeno-based attack lures gamers by claiming to offer an "undetected" cheat tool. Since gaming clients often flag and block known cheat tools, so-called "undetected" or premium cheats frequently act as bait. Make sure you steer clear of such tools.
  2. Use a third-party antivirus program: This is by far the most important step, not just to guard against this Roblox malware but for your device’s security in general. The malware resides on your system, so it could be detected by a reliable antivirus solution. If you have recently installed a cheat tool, run a full system scan using your antivirus software. If it detects anything malicious, it can quarantine the infected files and help remove the malware.
  3. Do not click on unsolicited links: Avoid clicking on links shared on gaming forums or Discord, especially those posted by strangers or suspicious accounts. Look out for accounts that were created recently or those that repeatedly promote cheat tools across gaming communities.
  4. Enable two-factor authentication (2FA) on all your gaming, social media, and financial accounts. This helps ensure that even if your password is compromised, an attacker is unlikely to access your accounts without a second authentication step, such as a temporary verification code that only you can access.
  5. Inspect any UAC prompts: Since the malware abuses the legitimate Windows CMSTP tool to escalate privileges, this action typically triggers a User Account Control (UAC) prompt. You may see a message such as, "Do you want to allow this app to make changes to your device?" If you notice such a prompt while installing an unknown file, don’t automatically click "Yes." This is a major red flag suggesting that the application is attempting to gain elevated privileges on your system.
  6. Use an identity theft protection service: If you have already interacted with such a cheat tool and are worried about your data being misused, a professional identity theft protection service can scan known breach databases and the dark web and alert you if it finds your personal information anywhere.

Bottom line

The new fake Xeno Roblox cheat hides as an "undetected" version of the Xeno Roblox script and is being increasingly shared on gaming forums and Discord. However, once you install the tool, it could give attackers near-complete control over your system.

Malicious actors could steal browser cookies, cryptocurrency wallet data, capture keystrokes, access your webcam, and even remotely modify your files. This could then be used to impersonate victims, collect sensitive images and information, and carry out financial fraud.

To stay safe, do not click on suspicious cheat links shared on gaming forums, especially if they are being heavily promoted. Also, enable 2FA on your critical accounts, run regular antivirus scans on your system, and consider using an identity theft protection service for even more airtight protection of your data.

#1 Antivirus Protection From an Award-Winning Brand You Trust
5.0
Editorial Rating
Get Deal
On Norton 360 Antivirus's website
2026 Editors’ Choice
Best All-In-One Antivirus
Antivirus Software
Norton 360 Antivirus
PROMOTION: Save Up to 60%
  • Our #1 rated antivirus that scores 18/18 on AV-TEST across Windows, macOS, and Android, verified across multiple test rounds
  • Passed every malware, drive-by download, and phishing detection test we ran, quarantining threats automatically
  • Backed by a 100% Virus Protection Promise: if Norton can't remove a virus, you get your money back

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums (Bitdefender)