New xlabs_v1 Botnet Targets Minecraft Servers Through ADB-Exposed Android Devices
ID: 19d00184-938f-56b9-a9ca-bc42fe89d4b2
STIX ID: report--19d00184-938f-56b9-a9ca-bc42fe89d4b2
Feed Name: cybersecurityNews.com
**xlabs_v1 Mirai-derived botnet targeting ADB-enabled devices:** Researchers discovered a Mirai variant called xlabs_v1 that infects devices with ADB exposed on TCP/5555 to recruit them into a DDoS-for-hire botnet specialized in flooding Minecraft servers; the report details infection steps (process masquerade, ChaCha20 string decryption, daemonization), C2 (xlabslover.lol:35342), fallback listener behavior, device profiling for pricing, and IOCs (IP 176.65.139.44, files under /data/local/tmp/arm7, outbound to pool.hashvault.pro), plus mitigation recommendations such as disabling ADB and blocking port 35342.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
