xlabs_v1
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Cybersecurity researchers have exposed a new Mirai-derived botnet that self-identifies as xlabs_v1 and targets internet-exposed devices running Android Debug Bridge (ADB) to enlist them in a network capable of carrying out distributed denial-of-service (DDoS) attacks.
Techniques & procedures
37 distinct techniques documented for this family, organized by ATT&CK tactic.
Reconnaissance
1 technique
Reconnaissance
Initial Access
1 technique
Initial Access
Execution
3 techniques
Execution
...the botnet engineered to receive an attack command from the operator's panel ('xlabslover[.]lol') and generate a flood of junk traffic on demand...
Persistence
1 technique
Persistence
Stealth
10 techniques
Stealth
Sensitive strings are stored encrypted in .rodata and decrypted on startup... The same key, the twelve-byte nonce... are reused across all sixteen decryption calls.
argv[0] is overwritten with the decrypted /bin/bash, a prctl call to set the kernel comm field updates the kernel's comm field
Once installed, the bot hides infection tags... It also kills competing botnets by scanning /proc, terminating rival processes, and removing malware on port 24936.
Defense Evasion T1070 T1070.004 File Deletion Every payload one-liner runs rm -rf * before installing the bot.
Persistence T1205 T1205 Traffic Signaling Bot listens on TCP/26721 for inbound operator re-entry when outbound C2 fails.
This assessment is based on the presence of a bandwidth-profiling routine that collects victim bandwidth and geolocation. This component opens 8,192 parallel TCP sockets to the geographically nearest Speedtest server... and reports the measured data transfer rate back to the panel.
Defense Impairment
1 technique
Defense Impairment
Discovery
3 techniques
Discovery
It also kills competing botnets by scanning /proc, terminating rival processes, and removing malware on port 24936.
CPU count, RAM size, hostname collected for C2 registration.
This assessment is based on the presence of a bandwidth-profiling routine that collects victim bandwidth and geolocation. This component opens 8,192 parallel TCP sockets to the geographically nearest Speedtest server... and reports the measured data transfer rate back to the panel.
Lateral Movement
2 techniques
Lateral Movement
Collection
1 technique
Collection
Command and Control
10 techniques
Command and Control
Sensitive strings, including the C2 domain xlabslover.lol, the operator handle Tadashi, and the agent tag xlabs_v1, are encrypted with ChaCha20 but easily recovered due to key reuse.
If outbound C2 fails, the bot falls through to a SOCKS-style fallback listener on TCP/26721
Its command-and-control uses a custom TCP protocol, supporting bandwidth probes, updates, self-restart, and attack dispatch.
...falls back to a firewall-punching SOCKS-style listener on TCP/26721... The directory held about 200 KB of data, including ... a SOCKS5 proxy...
If the outbound connection fails, it opens a fallback listener on TCP port 26721, punching through the firewall using five different iptables paths to keep the operator’s re-entry channel open.
Besides an Android APK ('boot.apk'), the malware supports multi-architecture builds... The bot is statically-linked ARMv7... and is delivered through ADB-shell pastes into /data/local/tmp...
Persistence T1205 T1205 Traffic Signaling Bot listens on TCP/26721 for inbound operator re-entry when outbound C2 fails.
Impact
5 techniques
Impact
The killer subsystem SIGKILLs competing bots; the rival-port-eviction routine targets port 24936.
It includes 21 flood techniques across TCP, UDP, and raw protocols... Its core function is to receive attack commands and launch one of 21 flood variants, many aimed at game servers, including RakNet floods for Minecraft and OpenVPN-shaped UDP traffic to evade filters.
21 flood variants across TCP, UDP, and raw protocols, including RakNet and OpenVPN-shaped UDP
The botnet is a modified version of the well-known Mirai malware, sold as a DDoS-for-hire service that lets paying customers flood game servers with traffic to take them offline. The botnet focuses on game-server disruption, with a dedicated RakNet flood variant built specifically to attack Minecraft servers...
IOCs tracked for this family
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mirai-based botnet built for commercial DDoS-for-hire operations. It compromises ADB-exposed IoT and Android-based devices, supports 21 flood techniques, profiles victim bandwidth, kills competing botnets, uses OpenNIC-aware DNS and fallback listener mechanisms for resilience, and communicates with a custom TCP C2 protocol.
A Mirai-derived botnet that targets internet-exposed Android and IoT devices with ADB enabled, recruits them into a DDoS-for-hire infrastructure, profiles victim bandwidth for service tiering, and includes a killer component to remove competing malware and maximize available upstream bandwidth for attacks against game servers.
A Mirai-derived botnet that compromises internet-exposed Android and IoT devices with open ADB port 5555, deploys a bot binary, connects to C2 infrastructure, kills competing malware, and is used as a DDoS-for-hire platform focused on disrupting Minecraft servers, including via a dedicated RakNet flood capability.
Mirai-derived IoT botnet used for DDoS-for-hire operations. It infects internet-exposed devices via ADB on TCP/5555, supports multi-architecture payloads, kills competing malware, profiles victim bandwidth for pricing tiers, uses OpenNIC/DNS and fallback listener mechanisms for resilience, and provides 21 flood variants including RakNet and OpenVPN-shaped UDP attacks.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.