logo

From Android TVs to routers: the xlabs_v1 Mirai-based botnet built for DDoS attacks

ID: ba55880d-0cf8-52ad-ac39-c4ad8ebd9830

STIX ID: report--ba55880d-0cf8-52ad-ac39-c4ad8ebd9830

Feed Name: Security Affairs

Threat Score
72/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Pierluigi Paganini

...
...

A Mirai-derived botnet called xlabs_v1 is actively exploiting Android Debug Bridge (TCP/5555) on internet-exposed IoT devices (Android TVs, set-top boxes, routers) to run a commercial DDoS-for-hire operation: it includes multi-architecture payloads, 21 distinct flood methods (targeting game/Minecraft servers among others), bandwidth profiling, ChaCha20-protected strings, and C2 infrastructure anchored at xlabslover.lol with hosts in 176.65.139.0/24; Hunt.io recovered exposed toolkits and debug builds that identified operator indicators (handle "Tadashi") and operational details.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.