logo

Mirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacks

ID: ca4319aa-0f18-514b-b5c6-ac6da92a3b77

STIX ID: report--ca4319aa-0f18-514b-b5c6-ac6da92a3b77

Feed Name: The Hacker News

Threat Score
68/100

Date Published: 2026-05-06

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Hunt.io discovered a Mirai-derived botnet dubbed xlabs_v1 that exploits exposed Android Debug Bridge (ADB) on port 5555 to install multi-architecture DDoS bots on Android TV boxes, set-top boxes, smart TVs, residential routers and IoT devices; the botnet supports 21 flood variants (TCP/UDP/raw, including game-targeted techniques), runs bandwidth-profiling to tier devices for a DDoS-for-hire service, contains a 'killer' to evict competing malware, and lacks persistence requiring re-infection — infrastructure indicators include operator panel xlabslover.lol and IPs such as 176.65.139.44 (and related Monero-mining activity on .42), with additional related activity observed by Darktrace from 103.177.110.202.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.