Fake Xeno and Roblox Utilities Used to Install Windows RAT, Microsoft Warns
2026-03-04T21:04:47Z•d6c3f80af1d65590c0b436d70a18c68bad6a434d182699ef98d0574dd5f19adf
1CampaignAeternumClawJackedEntra IDLOLBinsOAuthOpenClawad-cloakingai-securityattack-surface-reductionblockchain-c2botnetbrowser-exploitdata-breachfake-avastiot-vulnerabilitiesmalwarepayment-fraudphishingpolygonpowerShellshinyhuntersthird-party-appsvulnerability-managementwindows-rat
What happened
Multiple high-risk stories: Microsoft warns of fake Xeno and Roblox utilities spreading a Windows RAT using PowerShell and LOLBins; Oasis Security disclosed a critical “ClawJacked” vulnerability in OpenClaw that can let websites hijack AI agents via a browser tab; Qrator identified the Aeternum C2 botnet leveraging the Polygon blockchain for resilient command-and-control; ShinyHunters leaked 2M Odido records (claiming up to 21M); Varonis found the 1Campaign ad-cloaking platform used to hide phishing pages; fraudsters cloned Avast to run a €499 refund phishing scam; Entra ID OAuth consent risks
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- d6c3f80af1d65590c0b436d70a18c68bad6a434d182699ef98d0574dd5f19adf
- Enrichment time
- 2026-03-04T21:04:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.