Operator’s Debug Build Exposes xlabs_v1 DDoS-for-Hire Botnet

· Original article ↗

Summary

Researchers reverse-engineered xlabs_v1 after finding its toolkit in an unauthenticated directory. The Mirai-derived botnet targets internet-exposed ADB devices and offers 21 DDoS methods aimed at game servers.

Key points

  • An unauthenticated directory on a Netherlands-hosted server exposed the bot’s production binary, unstripped development build, infection scripts, and other toolkit files.
  • The bot infects devices through internet-exposed Android Debug Bridge (ADB) on TCP/5555, with builds for multiple architectures and Android devices.
  • The Mirai-derived botnet has 21 TCP, UDP, and raw-protocol flood methods, including variants targeting Minecraft and other game servers.
  • Researchers found bandwidth profiling used to tier compromised devices for the DDoS-for-hire service, along with process masquerading and mechanisms for operator re-entry.
  • Weak ChaCha20 key material and reuse of the same key, nonce, and counter enabled researchers to recover the encrypted string table, including C2 details and an operator token.
  • The report documents C2 and distribution infrastructure, host and network indicators, and file hashes to support detection and investigation.

Article Details

Attack Vectors
  • Internet-exposed Android Debug Bridge on TCP/5555 allows infection one-liners to be executed through adb shell. Payloads place architecture-specific binaries in /data/local/tmp and launch them.
  • Distribution hosts deliver multi-architecture bot binaries and infection scripts through HTTP and raw TCP listeners.
  • The bot receives commands through a length-prefixed binary protocol over TCP/35342, including attack dispatch, binary updates, restart, and bandwidth profiling.
  • When outbound C2 fails, the bot opens an inbound SOCKS5-like listener on TCP/26721 and adds iptables ACCEPT rules to permit operator re-entry.
  • Twenty-one registered attack variants generate TCP, UDP, and raw-protocol floods, including RakNet traffic targeting Minecraft servers, OpenVPN-shaped UDP, HTTP-template attacks, and connection-exhaustion attacks.
  • The bot removes competing socket-owning processes and specifically kills the process bound to TCP/24936.
Defensive Notes
  • Investigate internet-exposed TCP/5555 services to determine whether they provide ADB access. The reported 4,107,361 exposed hosts are not all confirmed to run ADB.
  • Monitor for outbound TCP/35342, inbound TCP/26721, and iptables INPUT rules permitting TCP/26721.
  • Look for /data/local/tmp/arm7, /tmp/.upd, and processes masquerading as /bin/bash without a controlling TTY.
  • The source identifies 3Wb5WfDEblAOkD0xF3OTPmxWe6cmsR within the first hundred bytes after a TCP handshake as a highly specific xlabs_v1 registration signature.
  • A memory dump of the running bot can recover decrypted C2 and authentication strings because they remain in memory after initialization.
  • Correlate the disappearance of a TCP/24936-bound process with earlier process listings to identify malware displaced by the bot.
  • Treat 8,192 simultaneous connections to Speedtest endpoints followed by bot termination as a bandwidth-profiling indicator. The bot requires reinfection after this operation.
  • The analyzed bot does not establish boot-time persistence through init scripts, systemd units, or cron jobs; it relies on ADB reinfection and a live-process fallback listener.
  • Revoke the exposed Decodo SOCKS5 credentials identified in the captured toolkit.
  • Do not attribute the co-located VLTRig operation to Tadashi solely from shared hosting. The article explicitly states that common ownership cannot be determined from the captured artifacts.
  • Treat the Germany-hosted certificate-linked endpoint as lower-confidence infrastructure rather than confirmed active C2.

Indicators of compromise

TypeIndicatorContext
DOMAINxlabslover[.]lolPrimary xlabs_v1 C2 domain recovered from the encrypted string table.
IPV4172[.]94[.]96[.]75Lower-confidence probable operator management endpoint linked to the C2 host through a shared RDP certificate; not confirmed as active C2.
IPV4176[.]65[.]139[.]134Primary C2 address shown in the certificate-pivot results.
IPV4176[.]65[.]139[.]42Operator distribution host serving infection scripts and multi-architecture binaries; also observed distributing VLTRig.
IPV4176[.]65[.]139[.]44Operator staging host exposing production and development binaries, payloads, proxy credentials, and target files.
IPV4176[.]65[.]139[.]9Operator-controlled distribution server used to deliver bot binaries.
SHA256079ae4f813939dd96b961ae288fb7f930649dfebb4884c13af95309a71f986f5SHA-256 of payloads.txt containing ADB infection one-liners.
SHA25631a60f9e0b5b4f0371f4130a184e27f79cefacb080a6273ccb1c9a908dc6ca9dSHA-256 of debug.o2, the non-stripped development build of the bot.
SHA2568367daa8ce633724157b8edd21d625de5ac56b8c2d983bbb283836162037f3c1SHA-256 of proxies.txt containing the operator's SOCKS5 proxy credentials.
SHA256a03705fc225dbcec7e3c2f06a258afe81b5d88aaff1368d10dd6ba4f0932be7cSHA-256 of the UPX-packed arm7 production bot.
SHA256f962cb443975065b91d4512a42a529a091726e1815be28ced0ebb9dff997931dSHA-256 of arm7.unpacked, generated during analysis from the production bot.
SHA256fa965ed784f7ec99e21475205cc177bb71ac7550b4015b4a4b3e232f032dcb91SHA-256 of targets.txt, a target-placeholder artifact recovered from the operator toolkit.

MITRE ATT&CK

T1008 · Fallback ChannelsFailure of outbound C2 causes the bot to expose an inbound SOCKS5-like listener with the same command dispatcher.T1027.002 · Software PackingThe production ARM32 bot is UPX-packed, unlike the exposed development build.T1027.013 · Encrypted/Encoded FileSixteen sensitive strings are encrypted with ChaCha20 and decrypted during startup.T1036.005 · Match Legitimate Resource Name or LocationThe bot overwrites argv[0] and sets the kernel comm field through prctl to appear as /bin/bash.T1057 · Process DiscoveryThe killer subsystem enumerates PID directories under /proc and examines executable paths and socket file descriptors.T1059.004 · Unix ShellNine infection one-liners execute through adb shell; the update command also invokes a wget, chmod, and execution chain through system().T1070.004 · File DeletionThe article's mapping states that each infection one-liner runs rm -rf * before installing the bot.T1082 · System Information DiscoveryC2 registration includes the victim hostname, CPU count, and RAM size.T1090.002 · External ProxyThe recovered toolkit contains a Decodo SOCKS5 URL with credentials, which the article identifies as operator egress for source-IP obfuscation.T1105 · Ingress Tool TransferInfection payloads download architecture-specific binaries, and opcode 0xFD downloads and executes an update from an operator-supplied URL.T1106 · Native APIThe bot uses execve to re-execute its own binary and native calls for process control and daemonization.T1119 · Automated CollectionThe bandwidth profiler automatically obtains victim location and public IP information, measures upstream throughput, and reports the result to C2.T1222.002 · Linux and Mac PermissionsPayloads use chmod +x to make the downloaded bot executable; the update command applies the same operation to /tmp/.upd.T1489 · Service StopThe bot SIGSTOPs and SIGKILLs competing socket-owning processes and separately kills the process bound to TCP/24936.T1498.001 · Direct Network FloodTwenty-one attack variants produce TCP, UDP, GRE-IP, and other raw flood traffic at the compromised host's maximum available rate.T1499.002 · Service Exhaustion FloodConnection-exhaustion variants hold large numbers of sockets open, including Slowloris-style holding behavior.T1499.003 · Application Exhaustion FloodThe HTTP-template raw-TCP variant uses request templates and, according to the article's mapping, chunked-abuse headers against application-layer defenses.T1562.004 · Disable or Modify System FirewallThe fallback routine tries five iptables command variants to add an INPUT ACCEPT rule for TCP/26721.T1571 · Non-Standard PortThe bot uses TCP/35342 for C2 and TCP/26721 for fallback access, while distribution uses several non-standard ports.T1595.001 · Scanning IP BlocksThe article's mapping reports operator scanning of IP ranges for exposed ADB on TCP/5555 before infection.

Threat Actors

Malware

Vendors

Products

Tools

Countries

Related Articles