Lots of reasons, diddly. Maybe they want to get a map of your site, to see everything you have that's visible on the web? It's a lot easier to use Xenu than clicking on links. Plus, Xenu will follow hidden links and perhaps expose some content that you don't want everyone to see. Or, perhaps they want to harvest your outbound links?
I don't know if Xenu obeys robots.txt, but I doubt it. If being spidered by Xenu bothers you, using user-agent exclusion will discourage the casual snooper.