Botnet Hijacks ADB-Exposed Android Devices to Target Minecraft Servers
ID: dabc6a2d-35da-582b-a11e-01ab9de0c324
STIX ID: report--dabc6a2d-35da-582b-a11e-01ab9de0c324
Feed Name: GBHackers
Researchers uncovered a Mirai-derived botnet, xlabs_v1, that scans for Android devices with ADB exposed on TCP/5555 and deploys multi-architecture payloads (ARM, MIPS, x86-64, APK) to build a rentable DDoS-for-hire service targeting Minecraft and other game servers; analysts recovered binaries, delivery scripts, a C2 domain (xlabslover.lol), hosting IPs, and the operator handle “Tadashi,” and recommend auditing for open TCP/5555, disabling ADB, and monitoring for the disclosed infrastructure and authentication tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
