New Roblox trojan will land you with a nasty PC infection

Trojan
(Image credit: Iaremenko Sergii / Shutterstock)

With nearly 50m active users, it’s no surprise that cybercriminals continue to target the popular online game Roblox with all manner of scams and attacks.

According to new research from Checkpoint, researchers from Avanan discovered a trojan file hidden inside the legitimate Synapse X scripting tool which is used to inject exploits or cheat codes into Roblox.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Cybercriminals have begun leveraging Synapse X to install a self-executing program on Windows PCs that installs library files into the Windows system folder. This has the potential to break applications, corrupt or remove data or even send information back to the cybercriminals responsible.

Avanan researchers first found the trojan file used in the latest round of Roblox attacks inside a customer’s OneDrive. While the customer could have uploaded it to their cloud storage by mistake, the cloud email and collaboration security company scanned the file and labeled it as malicious.

Putting family and even business PCs at risk

The specific version of Synapse X used in these attacks against Roblox users drops three files on a victim’s system with one of them being a backdoor trojan.

From here, the trojan installs library files (DLL) into the victim’s Windows system folder and this malicious code can be perpetually referenced by Windows and remain running.

In addition to being able to break applications and listen to files, these attacks are particularly concerning due to the fact that Roblox is mainly played by children. As a result, the trojan can easily be installed on a personal computer which may not even have antivirus software installed. However, there’s also a corporate risk, since employees working from home may let their children play Roblox on their business laptops.

After finding this new trojan targeting Roblox users, Avanan reached out to the Roblox Corporation and the two have been communicated via email with plans to connect further via phone regarding the issue.

The Roblox Corporation also reached out to TechRadar Pro with the following statement regarding Avanan's report:

“This report represents a misleading picture of this exploit, which is in Synapse X, not Roblox. Using third party services to circumvent specific systems is also against our Terms of Service. Roblox maintains many systems to keep our users safe and secure, and we prohibit attempts to bypass these systems or otherwise violate our platform requirements.”

In order to protect your devices from these kinds of attacks, Checkpoint recommends that users avoid downloading files from untrusted sites, use malware scanning when accessing cloud storage services like OneDrive and Google Drive and install an antivirus on all of their personal computers.

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
A white padlock on a dark digital background.
GitHub is hiding malware disguised as games, legitimate software
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Microsoft Teams and other Windows tools hijacked to hack corporate networks
A white padlock on a dark digital background.
Developers targeted by malicious Microsoft VSCode extensions
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
Magnifying glass enlarging the word 'malware' in computer machine code
Microsoft Teams and AnyDesk abused to deploy dangerous malware, so be on your guard
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
Latest in Security
ransomware avast
One of the most powerful ransomware hacks around has been cracked using some serious GPU power
person at a computer
Infamous ransomware hackers reveal new tool to brute-force VPNs
person at a computer
Many workers are overconfident at spotting phishing attacks
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Microsoft 365 accounts are under attack from new malware spoofing popular work apps
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Latest in News
Google DeepMind panel discussion
“More sovereignty and protection” - Google goes all-in on UK AI with data residency, upskilling projects, and startup investments
An image of the Nintendo Switch 2
Nintendo Switch 2 could have AI upscaling similar to PS5 Pro’s PSSR according to patent, and it could be a gamechanger for graphics on the upcoming console
PowerColor Red Devil AMD RX 9070 XT graphics card shown side-on
Your next GPU could be from AMD, not Nvidia, if Team Red’s success with PC gamers continues
Quordle on a smartphone held in a hand
Quordle hints and answers for Tuesday, March 18 (game #1149)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Tuesday, March 18 (game #380)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Tuesday, March 18 (game #646)