HomeSecurityxlabs_v1 Botnet: ADB Exploit for DDoS Attacks on IoT

xlabs_v1 Botnet: ADB Exploit for DDoS Attacks on IoT

The new xlabs_v1 botnet, based on Mirai, targets devices (exposed to the internet) running Android Debug Bridge (ADB)to join a network capable of performing distributed denial-of-service (DDoS). Cybersecurity researchers from Hunt.io discovered the malware after spotting an exposed directory on a server hosted in the Netherlands, with the IP address 176.65.139[.]44.

xlabs_v1 Botnet

xlabs_v1 Botnet: New threat

xlabs_v1 supports 21 flood attack variants on TCP , UDP and raw protocols , including RakNet and OpenVPN-shaped UDP , which are capable of bypassing consumer-grade DDoS protection . It is offered as a DDoS-for-hire service designed to target game servers and Minecraft hosts . What makes xlabs_v1 notable is that it looks for Android devices running an exposed ADB service on TCP port 5555 , meaning that any equipment that has the tool enabled by default, such as Android TV boxes , set-top boxes and smart TVs , could be a potential target.

See also: Masjesu Botnet: DDoS-for-Hire Service Targets IoT Devices

In addition to an Android APK file (“boot.apk”), the malware supports multi-architecture builds covering ARM, MIPS, x86-64 , and ARC, indicating that it is also designed to target residential routers and internet-of-things (IoT) hardware. The result is a specially crafted botnet designed to receive attack commands from the operator’s control panel (“xlabslover[.]lol”) and create a flood of junk traffic on demand.

Technical Details and Operating Mechanism of xlabs_v1

According to Hunt.io's analysis , the bot is statically-linked ARMv7, runs on stripped Android firmwares, and is delivered via ADB-shell pastes to the /data/local/tmp directory . The list of nine variants of the operator is configured for Android TV boxes , set-top boxes , smart TVs , and IoT-grade ARM hardware that ships with ADB enabled .

There is evidence to suggest that the DDoS-for-hire has pricing based on bandwidth levels. This estimate is based on the presence of a bandwidth-profiling routine that collects the victim's bandwidth and location. This component opens 8,192 parallel TCP connections to the geographically closest Speedtest, fills them for 10 seconds , and reports the measured data transfer rate back to the dashboard.

See also: Mirai Botnet targets Juniper smart routers

xlabs_v1 Botnet: ADB Exploit for DDoS Attacks on IoT

An important feature to note is that the botnet terminates after sending bandwidth information in Megabits per second (Mbps), meaning that the operator must re-infect the device a second time via the same ADB, given the absence of a persistence mechanism. The bot does not write itself to disk persistence locations, does not modify init scripts, does not create systemd units , and does not register cron jobs.

Competition and Attack Strategy

xlabs_v1 features a “killer” subsystem for terminating adversaries, so that it can hijack the full upstream bandwidth of the victim device and use it to execute the DDoS attack. It is not currently known who is behind the malware, but the threat actor uses the alias “Tadashi”, as evidenced by a ChaCha20-encrypted string embedded in each version of the bot.

Further analysis of the co-located infrastructure has revealed a VLTRig Monero-mining toolkit on host 176.65.139[.]42, although it is currently unknown whether the two sets of activities are the work of the same threat actor. In commercial-criminal terms, xlabs_v1 is mid-level. It is more sophisticated than the typical script-kiddie Mirai fork, but less sophisticated than the top-tier commercial DDoS-for-hire.

See also: Mirai-inspired Gorilla Botnet hits 0.3 million targets in 100 countries

This operator competes on price and variety of attacks, not technique. Consumer IoT devices, home routers, and small game-server operators are the targets. The discovery of this botnet highlights the ongoing threat that Mirai derivatives pose to IoT security , particularly when devices maintain default settings that expose services like ADB .

xlabs_v1 Botnet: ADB Exploit for DDoS Attacks on IoT

The use of exposed ADB services on Android TVs, routers, and smart devices turns simple household equipment into “weapons” for massive DDoS attacks, without most users realizing that their devices have been compromised. At the same time, the commercial dimension of xlabs_v1 shows that DDoS-for-hire services are becoming increasingly accessible, even to cybercriminals with limited technical knowledge.

At the same time, experts warn that the security of connected devices remains largely the responsibility of both manufacturers and users. Disabling services when not in use, changing default credentials, and regularly installing firmware updates are now considered essential protection measures. As long as millions of IoT devices remain exposed to the internet with inadequate security, botnets like xlabs_v1 will continue to pose a serious threat to the stability and security of the modern internet.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS