The Tadashi Files: Inside the xlabs_v1 Botnet Targeting 4 Million Android Devices
ID: 1692bc9f-7e76-53d8-ab34-32a26aba1560
STIX ID: report--1692bc9f-7e76-53d8-ab34-32a26aba1560
Feed Name: securityonline.info
Threat Score
Security researchers uncovered xlabs_v1, a Mirai-derived DDoS-for-hire botnet whose operator left binaries and infrastructure exposed; the bot targets Android Debug Bridge (TCP/5555) on IoT and consumer devices, implements 21 flood variants, bandwidth profiling to price-tier bots, evasion techniques (process renaming, killer module), and centralized C2/cryptojacking hosting in a Netherlands bulletproof netblock.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
