DDoS-for-Hire Operation Exposed: How an Operator's Debug Build Unraveled a Commercial Game-Server Botnet

April 30, 2026, 8:17 a.m.

Description

An exposed open directory on a Netherlands-hosted server revealed the complete operational toolkit of xlabs_v1, a Mirai-derived IoT botnet operated by an actor using the handle Tadashi. The operation provides DDoS-for-hire services specifically targeting game servers and Minecraft hosts through 21 distinct flood attack variants. The botnet exploits Android Debug Bridge (ADB) on TCP/5555 to compromise over 4 million potentially vulnerable IoT devices including Android TV boxes, smart TVs, and routers. The operation features bandwidth profiling to price-tier infected devices, ChaCha20 string encryption with cryptographic weaknesses, and competitor-eradication routines. Infrastructure analysis consolidated the entire operation within a single bulletproof /24 netblock in the Netherlands, with co-located cryptojacking infrastructure also identified.

Date

  • Created: April 29, 2026, 7:42 p.m.
  • Published: April 29, 2026, 7:42 p.m.
  • Modified: April 30, 2026, 8:17 a.m.

Indicators

  • 31a60f9e0b5b4f0371f4130a184e27f79cefacb080a6273ccb1c9a908dc6ca9d
  • fa965ed784f7ec99e21475205cc177bb71ac7550b4015b4a4b3e232f032dcb91
  • 8367daa8ce633724157b8edd21d625de5ac56b8c2d983bbb283836162037f3c1
  • f962cb443975065b91d4512a42a529a091726e1815be28ced0ebb9dff997931d
  • 079ae4f813939dd96b961ae288fb7f930649dfebb4884c13af95309a71f986f5
  • a03705fc225dbcec7e3c2f06a258afe81b5d88aaff1368d10dd6ba4f0932be7c
  • 176.65.139.134
  • 176.65.139.42
  • 176.65.139.9
  • 176.65.139.44

Attack Patterns

Additional Informations

  • Hospitality