Fake Xeno and Roblox Utilities Used to Install Windows RAT, Microsoft Warns

2026-03-04T21:04:47Zd6c3f80af1d65590c0b436d70a18c68bad6a434d182699ef98d0574dd5f19adf
1CampaignAeternumClawJackedEntra IDLOLBinsOAuthOpenClawad-cloakingai-securityattack-surface-reductionblockchain-c2botnetbrowser-exploitdata-breachfake-avastiot-vulnerabilitiesmalwarepayment-fraudphishingpolygonpowerShellshinyhuntersthird-party-appsvulnerability-managementwindows-rat

What happened

Multiple high-risk stories: Microsoft warns of fake Xeno and Roblox utilities spreading a Windows RAT using PowerShell and LOLBins; Oasis Security disclosed a critical “ClawJacked” vulnerability in OpenClaw that can let websites hijack AI agents via a browser tab; Qrator identified the Aeternum C2 botnet leveraging the Polygon blockchain for resilient command-and-control; ShinyHunters leaked 2M Odido records (claiming up to 21M); Varonis found the 1Campaign ad-cloaking platform used to hide phishing pages; fraudsters cloned Avast to run a €499 refund phishing scam; Entra ID OAuth consent risks

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
d6c3f80af1d65590c0b436d70a18c68bad6a434d182699ef98d0574dd5f19adf
Enrichment time
2026-03-04T21:04:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Fake Xeno and Roblox Utilities Used to Install Windows RAT, Microsoft Warns · Baitaphish