logo

Botnet Hijacks ADB-Exposed Android Devices to Target Minecraft Servers

ID: dabc6a2d-35da-582b-a11e-01ab9de0c324

STIX ID: report--dabc6a2d-35da-582b-a11e-01ab9de0c324

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-05-04

Date Updated: 2026-05-11

Author: Mayura Kathir

...
...

Researchers uncovered a Mirai-derived botnet, xlabs_v1, that scans for Android devices with ADB exposed on TCP/5555 and deploys multi-architecture payloads (ARM, MIPS, x86-64, APK) to build a rentable DDoS-for-hire service targeting Minecraft and other game servers; analysts recovered binaries, delivery scripts, a C2 domain (xlabslover.lol), hosting IPs, and the operator handle “Tadashi,” and recommend auditing for open TCP/5555, disabling ADB, and monitoring for the disclosed infrastructure and authentication tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.