Operator’s Debug Build Exposes xlabs_v1 DDoS-for-Hire Botnet

Summary
Researchers reverse-engineered xlabs_v1 after finding its toolkit in an unauthenticated directory. The Mirai-derived botnet targets internet-exposed ADB devices and offers 21 DDoS methods aimed at game servers.
Key points
- An unauthenticated directory on a Netherlands-hosted server exposed the bot’s production binary, unstripped development build, infection scripts, and other toolkit files.
- The bot infects devices through internet-exposed Android Debug Bridge (ADB) on TCP/5555, with builds for multiple architectures and Android devices.
- The Mirai-derived botnet has 21 TCP, UDP, and raw-protocol flood methods, including variants targeting Minecraft and other game servers.
- Researchers found bandwidth profiling used to tier compromised devices for the DDoS-for-hire service, along with process masquerading and mechanisms for operator re-entry.
- Weak ChaCha20 key material and reuse of the same key, nonce, and counter enabled researchers to recover the encrypted string table, including C2 details and an operator token.
- The report documents C2 and distribution infrastructure, host and network indicators, and file hashes to support detection and investigation.
Article Details
- Attack Vectors
- Internet-exposed Android Debug Bridge on TCP/5555 allows infection one-liners to be executed through adb shell. Payloads place architecture-specific binaries in /data/local/tmp and launch them.
- Distribution hosts deliver multi-architecture bot binaries and infection scripts through HTTP and raw TCP listeners.
- The bot receives commands through a length-prefixed binary protocol over TCP/35342, including attack dispatch, binary updates, restart, and bandwidth profiling.
- When outbound C2 fails, the bot opens an inbound SOCKS5-like listener on TCP/26721 and adds iptables ACCEPT rules to permit operator re-entry.
- Twenty-one registered attack variants generate TCP, UDP, and raw-protocol floods, including RakNet traffic targeting Minecraft servers, OpenVPN-shaped UDP, HTTP-template attacks, and connection-exhaustion attacks.
- The bot removes competing socket-owning processes and specifically kills the process bound to TCP/24936.
- Defensive Notes
- Investigate internet-exposed TCP/5555 services to determine whether they provide ADB access. The reported 4,107,361 exposed hosts are not all confirmed to run ADB.
- Monitor for outbound TCP/35342, inbound TCP/26721, and iptables INPUT rules permitting TCP/26721.
- Look for /data/local/tmp/arm7, /tmp/.upd, and processes masquerading as /bin/bash without a controlling TTY.
- The source identifies 3Wb5WfDEblAOkD0xF3OTPmxWe6cmsR within the first hundred bytes after a TCP handshake as a highly specific xlabs_v1 registration signature.
- A memory dump of the running bot can recover decrypted C2 and authentication strings because they remain in memory after initialization.
- Correlate the disappearance of a TCP/24936-bound process with earlier process listings to identify malware displaced by the bot.
- Treat 8,192 simultaneous connections to Speedtest endpoints followed by bot termination as a bandwidth-profiling indicator. The bot requires reinfection after this operation.
- The analyzed bot does not establish boot-time persistence through init scripts, systemd units, or cron jobs; it relies on ADB reinfection and a live-process fallback listener.
- Revoke the exposed Decodo SOCKS5 credentials identified in the captured toolkit.
- Do not attribute the co-located VLTRig operation to Tadashi solely from shared hosting. The article explicitly states that common ownership cannot be determined from the captured artifacts.
- Treat the Germany-hosted certificate-linked endpoint as lower-confidence infrastructure rather than confirmed active C2.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | xlabslover[.]lol | Primary xlabs_v1 C2 domain recovered from the encrypted string table. |
| IPV4 | 172[.]94[.]96[.]75 | Lower-confidence probable operator management endpoint linked to the C2 host through a shared RDP certificate; not confirmed as active C2. |
| IPV4 | 176[.]65[.]139[.]134 | Primary C2 address shown in the certificate-pivot results. |
| IPV4 | 176[.]65[.]139[.]42 | Operator distribution host serving infection scripts and multi-architecture binaries; also observed distributing VLTRig. |
| IPV4 | 176[.]65[.]139[.]44 | Operator staging host exposing production and development binaries, payloads, proxy credentials, and target files. |
| IPV4 | 176[.]65[.]139[.]9 | Operator-controlled distribution server used to deliver bot binaries. |
| SHA256 | 079ae4f813939dd96b961ae288fb7f930649dfebb4884c13af95309a71f986f5 | SHA-256 of payloads.txt containing ADB infection one-liners. |
| SHA256 | 31a60f9e0b5b4f0371f4130a184e27f79cefacb080a6273ccb1c9a908dc6ca9d | SHA-256 of debug.o2, the non-stripped development build of the bot. |
| SHA256 | 8367daa8ce633724157b8edd21d625de5ac56b8c2d983bbb283836162037f3c1 | SHA-256 of proxies.txt containing the operator's SOCKS5 proxy credentials. |
| SHA256 | a03705fc225dbcec7e3c2f06a258afe81b5d88aaff1368d10dd6ba4f0932be7c | SHA-256 of the UPX-packed arm7 production bot. |
| SHA256 | f962cb443975065b91d4512a42a529a091726e1815be28ced0ebb9dff997931d | SHA-256 of arm7.unpacked, generated during analysis from the production bot. |
| SHA256 | fa965ed784f7ec99e21475205cc177bb71ac7550b4015b4a4b3e232f032dcb91 | SHA-256 of targets.txt, a target-placeholder artifact recovered from the operator toolkit. |
MITRE ATT&CK
T1008 · Fallback ChannelsFailure of outbound C2 causes the bot to expose an inbound SOCKS5-like listener with the same command dispatcher.T1027.002 · Software PackingThe production ARM32 bot is UPX-packed, unlike the exposed development build.T1027.013 · Encrypted/Encoded FileSixteen sensitive strings are encrypted with ChaCha20 and decrypted during startup.T1036.005 · Match Legitimate Resource Name or LocationThe bot overwrites argv[0] and sets the kernel comm field through prctl to appear as /bin/bash.T1057 · Process DiscoveryThe killer subsystem enumerates PID directories under /proc and examines executable paths and socket file descriptors.T1059.004 · Unix ShellNine infection one-liners execute through adb shell; the update command also invokes a wget, chmod, and execution chain through system().T1070.004 · File DeletionThe article's mapping states that each infection one-liner runs rm -rf * before installing the bot.T1082 · System Information DiscoveryC2 registration includes the victim hostname, CPU count, and RAM size.T1090.002 · External ProxyThe recovered toolkit contains a Decodo SOCKS5 URL with credentials, which the article identifies as operator egress for source-IP obfuscation.T1105 · Ingress Tool TransferInfection payloads download architecture-specific binaries, and opcode 0xFD downloads and executes an update from an operator-supplied URL.T1106 · Native APIThe bot uses execve to re-execute its own binary and native calls for process control and daemonization.T1119 · Automated CollectionThe bandwidth profiler automatically obtains victim location and public IP information, measures upstream throughput, and reports the result to C2.T1222.002 · Linux and Mac PermissionsPayloads use chmod +x to make the downloaded bot executable; the update command applies the same operation to /tmp/.upd.T1489 · Service StopThe bot SIGSTOPs and SIGKILLs competing socket-owning processes and separately kills the process bound to TCP/24936.T1498.001 · Direct Network FloodTwenty-one attack variants produce TCP, UDP, GRE-IP, and other raw flood traffic at the compromised host's maximum available rate.T1499.002 · Service Exhaustion FloodConnection-exhaustion variants hold large numbers of sockets open, including Slowloris-style holding behavior.T1499.003 · Application Exhaustion FloodThe HTTP-template raw-TCP variant uses request templates and, according to the article's mapping, chunked-abuse headers against application-layer defenses.T1562.004 · Disable or Modify System FirewallThe fallback routine tries five iptables command variants to add an INPUT ACCEPT rule for TCP/26721.T1571 · Non-Standard PortThe bot uses TCP/35342 for C2 and TCP/26721 for fallback access, while distribution uses several non-standard ports.T1595.001 · Scanning IP BlocksThe article's mapping reports operator scanning of IP ranges for exposed ADB on TCP/5555 before infection.
Threat Actors
Malware
MiraiMirai-derived botnet, self-branded xlabs_v1, operated by Tadashi, sold as a DDoS-for-hire service targeting game servers and Minecraft hosts with bandwidth-tiered pricing.VLTRiginfrastructure within the same 176.65.139[.]0/24 netblock has previously been observed distributing the VLTRig Monero-mining toolkit on host 176.65.139[.]42. Independent samples of the VLTRig deployment scripts usexlab 2as during operator testing), it surfaces and reveals the operator's active rivalry with a fork called xlab 2.xlabs_v1table through known-plaintext analysis, and mapping the wire protocol gave us a complete picture of how xlabs_v1 operates, what it targets, the infrastructure behind it, and who is running it.
Vendors
Decodobits per byte, the same key/nonce/counter triple reused across all sixteen decryption calls, the Decodo SOCKS5 credentials sitting in plaintext on the same exposed staging server, and the operator's rivalryGSL Networks Pty Ltdand 172.94.96[.]75 (Germany).Querying 172.94.96[.]75 directly (Figure 20) shows it is hosted by GSL Networks Pty Ltd in Frankfurt, Germany (AS137409, 172.94.96.0/24). Unlike the Netherlands C2 IP, this host carriesOffshore LCFull operation consolidated within a single bulletproof /24 (Offshore LC, AS214472, Netherlands), including C2, distribution, staging, and co-located Monero cryptojacking infrastructure.Telchak Gold Ventures(last seen October 2025) and 172.94.96[.]75 on TCP/3389 (last seen September 2025, hosted by Telchak Gold Ventures in Germany). The same self-signed RDP certificate appearing across two geographically distinctUltahostThe domain resolves to a single A record at 176.65.139[.]134, with nameservice delegated entirely to Ultahost infrastructure (ns1--ns4.ultahost.com). No WHOIS registrar data is present, a common pattern for domains
Products
AndroidInfection vector is Android Debug Bridge on TCP/5555, with multi-architecture builds covering ARM, MIPS, x86-64, ARC, and Android APK, meaning any internet-exposed device running ADB is a potential target: Android TVMinecraftMirai-derived botnet, self-branded xlabs_v1, operated by Tadashi, sold as a DDoS-for-hire service targeting game servers and Minecraft hosts with bandwidth-tiered pricing.
Tools
Attack Capture File ManagerOur investigation began with the discovery of an Attack Capture File Manager web interface exposed on TCP/80 of 176.65.139[.]44, a host announced by Offshore LC out of the Netherlands, showing clear signs of a MiraiAttackCaptureof bulletproof-hosting netblocks in early April 2026, our open directory intelligence tool AttackCapture⢠flagged an exposed directory on a Netherlands-hosted server at 176.65[.]139.44 The operator leftHuntSQLFigure 4. HuntSQL results showing 4,107,361 internet-exposed hosts with TCP/5555 open in the past 180 days.With the infection surface mapped, we turned to the binaries themselves to understand how xlabs_v1 behaves onceIDAFigure 12. IDA Strings panel filtered for [aterna], showing the development build's retained log telemetry. Each line in this list corresponds to a printf statement that the production build has stripped.The internalnetcatThe deca string passed as argv[1] by the netcat-based payload variants is captured into an internal thirty-two-byte ID buffer and then overwritten with zeros in the original argument vector. From this point forward, psUPXbinaries, infection payloads, proxy credentials, and a target placeholder. The production ARM32 binary was UPX-packed and stripped. The development build wasn't. Cross-referencing both, recovering the ChaCha20 string
Countries
Germany2025) and 172.94.96[.]75 on TCP/3389 (last seen September 2025, hosted by Telchak Gold Ventures in Germany). The same self-signed RDP certificate appearing across two geographically distinct hosts operated byNetherlandsApril 2026, our open directory intelligence tool AttackCapture⢠flagged an exposed directory on a Netherlands-hosted server at 176.65[.]139.44 The operator left their full toolkit publicly accessible on TCP/80