Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Tadashi

Also known as: Fancy Bear, Forest Blizzard, Sofacy, Pawn Storm, Sednit, STRONTIUM, Cozy Bear, Midnight Blizzard, The Dukes, Nobelium, YTTRIUM, Voodoo Bear, Seashell Blizzard, IRIDIUM, Telebots, Iron Viking, Secret Blizzard, Snake, Venomous Bear, Uroburos, Waterbug, KRYPTON, Aqua Blizzard, Primitive Bear, Shuckworm, Armageddon, Actinium, Double Dragon, Brass Typhoon, Wicked Panda, Winnti, Barium, Leviathan, Gingham Typhoon, TEMP.Periscope, TEMP.Jumper, Bronze Mohawk, Volt Typhoon, Vanguard Panda, Bronze Silhouette, Group 88, Turla Team, Krypton, SIG23, MAKERSMARK, IRON HUNTER, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, Blue Echidna, FROZENBARENTS, UAC-0113, UAC-0082, APT44, BRONZE MOHAWK, GADOLINIUM, KRYPTONITE PANDA, G0065, ATK29, TA423, Red Ladon, ITG09, MUDCARP, ISLANDDREAMS, TG-2633, Winnti Umbrella, BRONZE ATLAS, ISLAND CASTLE, DarkHalo, StellarParticle, NOBELIUM, Solar Phoenix

Description

The actor named Tadashi was first identified when defenders discovered an exposed open directory on a server hosted in the Netherlands that contained the entire operational toolkit of xlabs_v1, a Mirai derivative botnet. The toolkit demonstrates automated exploitation of Android Debug Bridge (ADB) connections over TCP/5555 to infect more than four million IoT devices—including Android TV boxes, smart TVs, and commercial routers—by leveraging default credentials or vulnerable firmware. Once compromised, infected hosts become part of a centrally managed network that delivers DDoS-for-hire services. The operation offers a spectrum of 21 distinct flood attack variants specifically tuned against game servers, with emphasis on Minecraft hosting providers. A bandwidth‑profiling system assigns price tiers to clients and includes competitor-eradication routines designed to remove competing botnets from infected devices. In addition to DDoS operations, Tadashi incorporates lightweight cryptojacking modules that mine cryptocurrency on infected machines, thereby diversifying revenue streams. All communications with the command‑and‑control infrastructure are encrypted using ChaCha20, albeit with identified key management weaknesses that could be exploited for traffic analysis or takedown efforts.

Goals & Targeting

Targeted Sectors

Information technology
Government
Defense
Telecommunications
Financial services
Critical infrastructure
Energy
Education
Healthcare
Media
Aerospace
Non profit
Nuclear
Think tank
Gaming
Maritime
Pharmaceutical
Transportation
Legal services
Hospitality
Entertainment
Manufacturing
Technology

Targeted Countries / Regions

CN
UA
IR
IL
SA
AE
RU
VN
TR
KP
GB
europe

AI Analysis

Grounded in web research
· 2 days ago

Executive Summary

Actor named Tadashi operates a Mirai‑derived IoT botnet called xlabs_v1 that delivers DDoS-for-hire services targeting game servers, notably Minecraft hosts. The botnet leverages Android Debug Bridge on port 5555 to compromise millions of vulnerable devices, employs ChaCha20 encryption with weaknesses, and is housed behind a single bulletproof /24 netblock in the Netherlands. Financial gain through paid attack tiers and ancillary cryptojacking infrastructure appears to be the primary motivation.

Goals & Targeting

Strategic objectives of Tadashi appear to be purely financial: monetizing a large-scale IoT botnet through a paid DDoS-for-hire business model. The actor targets high‑value, cost‑sensitive sectors such as online gaming and virtual server hosting where even brief downtime can result in direct monetary loss for service providers and end‑users. Victims are typically small to medium‑sized game server operators or individuals hosting community servers; the choice of target is driven by the availability of exploitable IoT devices and the potential for high billing rates from clients demanding large bandwidth attacks.

Enhanced Description

Key Capabilities

  • Mirai‑derived IoT botnet (xlabs_v1)
  • Automated exploitation of Android Debug Bridge over TCP/5555
  • Compromise of >4 M Android‑TV and router devices worldwide
  • Provision of DDoS-for‑hire services with multiple flood variants
  • Bandwidth profiling and tiered pricing model
  • ChaCha20 encryption with identified weaknesses in key management
  • Competing botnet detection and eradication routines
  • Hosting infrastructure within a single bulletproof /24 netblock in the Netherlands
  • Cryptojacking capabilities integrated into compromised machines

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Command and Control
Resource Hijacking
Defense Evasion

ATT&CK Techniques

T1105
T1203
T1046
T1071.001
T1498

Software / Tooling

xlabs_v1
Mirai derivative
ChaCha20 encryption module
ADB exploitation script
Cryptocurrency miner
DDoS packet generator

Campaigns & Victims

First known activity surfaced via an exposed open directory in the Netherlands; Tadashi has consistently used a single bulletproof netblock, indicating a dedicated command‑and‑control infrastructure. The operation structures DDoS offerings around price-tiered bandwidth provisions and maintains competitor-eradication routines to reduce lateral movement from other botnets. The presence of cryptojacking subsystems suggests revenue diversification: infected devices run lightweight mining scripts after initial payload delivery, creating multiple income streams for the actor.

IOC Patterns

  • Open directory listing exposing xlabs_v1 binaries
  • Outbound traffic to a /24 netblock in the Netherlands via TCP/5555 (ADB)
  • ChaCha20‑encrypted C2 communication to IPs within that netblock
  • DDoS traffic signatures targeting Minecraft server ports
  • Cryptocurrency mining process named 'miner' on infected devices

Recommended Actions

  • Block outbound DNS and HTTP(S) requests to known C2 netblocks identified for Tadashi.
  • Implement firewall rules to reject unsolicited traffic to port 5555 (ADB) from external sources.
  • Apply hardening guidelines to all Android‑based IoT devices, disabling remote debugging features by default.
  • Deploy a DDoS mitigation service or appliance that deflects volumetric floods against game hosting environments.
  • Monitor for suspicious cryptojacking signatures and terminate unknown miner processes on corporate endpoints.

Suggested Tags

APT
DDoS-for-hire
Botnet
IoT
Gaming industry
Cryptojacking
Financial motive
Mirai derivative

Confidence Assessment

Confidence is moderate in the attribution of the botnet activity to an actor named Tadashi based on the discovered open directory and the presence of a Mirai‑derived code base; however, associations with any other known APT aliases remain unverified due to lack of corroborating indicators. The functional profile (IoT exploitation via ADB, DDoS-for-hire, cryptojacking) is well‑documented, but details about long‑term operational plans, insider support, or state sponsorship are not supported by current evidence.

ATT&CK Techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 4 IPv4 Address 1 MD5 3 SHA1 3 IPV4 1 SHA256 6

References

No references recorded yet.

Intel Summary

5

Techniques

20

Tools

7

Campaigns

18

IOCs

0

Observed Data

4

Tactics

Tags

Critical Infrastructure
DDoS
APT
IoT botnet
Financial gain
Cybercrime
DDoS-for-hire
Botnet
IoT
Gaming industry
Cryptojacking
Financial motive
Mirai derivative

Details

Type
Apt
Resource Level
Government
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
50%
Added
May 3, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.