Hunt.io Exposes Mirai‑Derived xlabs_v1 Botnet Targeting ADB‑Exposed Devices
Patch or secure Android Debug Bridge on all devices to prevent enlistment in the xlabs_v1 Mirai‑derived botnet.
Patch or secure Android Debug Bridge on all devices to prevent enlistment in the xlabs_v1 Mirai‑derived botnet.
Summary
Cybersecurity researchers at Hunt.io uncovered a new Mirai‑derived botnet that self‑identifies as xlabs_v1. The malware targets internet‑exposed devices running Android Debug Bridge (ADB), recruiting them into a distributed denial‑of‑service (DDoS) network. The discovery was triggered by the detection of an exposed directory on a Netherlands‑hosted server, which revealed the botnet’s command‑and‑control infrastructure. xlabs_v1 leverages the same infection vectors used by Mirai, exploiting open ADB ports to gain remote access to devices.
Once compromised, the devices are enlisted to launch coordinated DDoS attacks against victim targets, potentially overwhelming networks and services. The botnet’s Mirai lineage suggests it may use similar payloads and command structures, making it a significant threat to IoT and mobile device ecosystems. Hunt.io recommends securing ADB access and monitoring for anomalous outbound traffic to mitigate the risk of enlistment.
Key changes
- New Mirai‑derived botnet named xlabs_v1
- Targets internet‑exposed devices running Android Debug Bridge (ADB)
- Enlists devices into a distributed denial‑of‑service (DDoS) network
- Discovery triggered by exposed directory on Netherlands‑hosted server
- xlabs_v1 uses Mirai infection vectors exploiting open ADB ports
- Compromised devices launch coordinated DDoS attacks
- Botnet’s Mirai lineage indicates similar payloads and command structures
- Hunt.io recommends securing ADB access and monitoring outbound traffic