Also known as: Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm, Sednit, STRONTIUM, Cozy Bear, Midnight Blizzard, The Dukes, Nobelium, YTTRIUM, Voodoo Bear, Seashell Blizzard, IRIDIUM, Telebots, Iron Viking, Secret Blizzard, Snake, Venomous Bear, Uroburos, Waterbug, KRYPTON, Aqua Blizzard, Primitive Bear, Shuckworm, Armageddon, Actinium, Double Dragon, Brass Typhoon, Wicked Panda, Winnti, Barium, Leviathan, Gingham Typhoon, TEMP.Periscope, TEMP.Jumper, Bronze Mohawk, Volt Typhoon, Vanguard Panda, Bronze Silhouette, Group 88, Turla Team, Krypton, SIG23, MAKERSMARK, IRON HUNTER, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, Blue Echidna, FROZENBARENTS, UAC-0113, UAC-0082, APT44, BRONZE MOHAWK, GADOLINIUM, KRYPTONITE PANDA, G0065, ATK29, TA423, Red Ladon, ITG09, MUDCARP, ISLANDDREAMS, TG-2633, Winnti Umbrella, BRONZE ATLAS, ISLAND CASTLE, DarkHalo, StellarParticle, NOBELIUM, Solar Phoenix
The actor named Tadashi was first identified when defenders discovered an exposed open directory on a server hosted in the Netherlands that contained the entire operational toolkit of xlabs_v1, a Mirai derivative botnet. The toolkit demonstrates automated exploitation of Android Debug Bridge (ADB) connections over TCP/5555 to infect more than four million IoT devices—including Android TV boxes, smart TVs, and commercial routers—by leveraging default credentials or vulnerable firmware. Once compromised, infected hosts become part of a centrally managed network that delivers DDoS-for-hire services. The operation offers a spectrum of 21 distinct flood attack variants specifically tuned against game servers, with emphasis on Minecraft hosting providers. A bandwidth‑profiling system assigns price tiers to clients and includes competitor-eradication routines designed to remove competing botnets from infected devices. In addition to DDoS operations, Tadashi incorporates lightweight cryptojacking modules that mine cryptocurrency on infected machines, thereby diversifying revenue streams. All communications with the command‑and‑control infrastructure are encrypted using ChaCha20, albeit with identified key management weaknesses that could be exploited for traffic analysis or takedown efforts.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Actor named Tadashi operates a Mirai‑derived IoT botnet called xlabs_v1 that delivers DDoS-for-hire services targeting game servers, notably Minecraft hosts. The botnet leverages Android Debug Bridge on port 5555 to compromise millions of vulnerable devices, employs ChaCha20 encryption with weaknesses, and is housed behind a single bulletproof /24 netblock in the Netherlands. Financial gain through paid attack tiers and ancillary cryptojacking infrastructure appears to be the primary motivation.
Goals & Targeting
Strategic objectives of Tadashi appear to be purely financial: monetizing a large-scale IoT botnet through a paid DDoS-for-hire business model. The actor targets high‑value, cost‑sensitive sectors such as online gaming and virtual server hosting where even brief downtime can result in direct monetary loss for service providers and end‑users. Victims are typically small to medium‑sized game server operators or individuals hosting community servers; the choice of target is driven by the availability of exploitable IoT devices and the potential for high billing rates from clients demanding large bandwidth attacks.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
First known activity surfaced via an exposed open directory in the Netherlands; Tadashi has consistently used a single bulletproof netblock, indicating a dedicated command‑and‑control infrastructure. The operation structures DDoS offerings around price-tiered bandwidth provisions and maintains competitor-eradication routines to reduce lateral movement from other botnets. The presence of cryptojacking subsystems suggests revenue diversification: infected devices run lightweight mining scripts after initial payload delivery, creating multiple income streams for the actor.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is moderate in the attribution of the botnet activity to an actor named Tadashi based on the discovered open directory and the presence of a Mirai‑derived code base; however, associations with any other known APT aliases remain unverified due to lack of corroborating indicators. The functional profile (IoT exploitation via ADB, DDoS-for-hire, cryptojacking) is well‑documented, but details about long‑term operational plans, insider support, or state sponsorship are not supported by current evidence.
Satellite Turla
Epic Turla
The 'Penquin' Turla
Witchcoven
RUAG hack
Mosquito
Moonlight Maze
No observed data linked yet.
No references recorded yet.
5
Techniques
20
Tools
7
Campaigns
18
IOCs
0
Observed Data
4
Tactics