← Back to news

From Android TVs to routers: the xlabs_v1 Mirai-based botnet built for DDoS attacks

Security Affairs07/05/2026, 10:15
Read full article →

Summary

AI-Generated

Key Points:

  • A new Mirai-based botnet, xlabs_v1, is exploiting ADB-exposed IoT devices to conduct large-scale DDoS attacks, with a focus on gaming servers.
  • The botnet utilizes 21 different flooding methods and targets devices such as Android TVs and residential routers, potentially affecting millions of vulnerable systems.
  • Security teams should monitor for ADB exposure on devices, implement network segmentation, and consider blocking TCP/5555 to mitigate the risk of exploitation.

Technical Details: The xlabs_v1 botnet leverages the Android Debug Bridge (ADB) on TCP/5555 for infection, utilizing various architectures including ARM and x86-64. The command-and-control (C2) domain is xlabslover.lol, which resolves to an IP address in the Netherlands.

MITRE ATT&CK Techniques:

  • T1071.001 - Application Layer Protocol: Web Protocols (Command and Control)
  • T1203 - Exploit Public-Facing Application (Initial Access)
  • T1499 - Endpoint Denial of Service (Impact)

IOCs Mentioned:

  • C2 Domain: xlabslover.lol
  • IP Address: 176.65.139.44

This summary provides actionable intelligence regarding the xlabs_v1 botnet's capabilities and recommended defensive measures against its exploitation.

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.