logo

ADB-Exposed Android Devices Used to Attack Minecraft Servers

ID: c926e558-1051-56ef-8e6d-ece75f6248a9

STIX ID: report--c926e558-1051-56ef-8e6d-ece75f6248a9

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-05-04

Date Updated: 2026-05-05

Author: Varshini

...
...

Researchers discovered an exposed staging server that revealed a Mirai-derived botnet called xlabs_v1, a commercial DDoS-for-hire service run by an actor named “Tadashi.” The malware infects devices via open Android Debug Bridge (TCP/5555), implements 21 specialized network-flood variants (including Minecraft-targeted RakNet floods), profiles device bandwidth by opening 8,192 parallel Speedtest connections to tier bots for pricing, kills competing botnets, disguises itself as /bin/bash, and uses weakly implemented ChaCha20 encryption; key infrastructure includes IP 176.65.139.44 and the domain xlabslover.lol.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.