Tadashi is the moniker associated with an operator behind xlabs_v1, a Mirai-derived botnet used for distributed denial-of-service activity. Attribution beyond the embedded Tadashi name is currently not available. The operation has been assessed as a DDoS-for-hire service focused primarily on gaming-related targets, especially game servers and Minecraft hosting infrastructure. The botnet targets internet-exposed Android Debug Bridge services to compromise Android-based devices and other IoT hardware, including consumer devices such as Android TV boxes, set-top boxes, smart TVs, and potentially residential routers through multi-architecture payload support. Its malware supports numerous flood methods across TCP, UDP, and raw protocols, including game-relevant traffic patterns, indicating deliberate optimization for denial-of-service attacks against gaming services. Operationally, xlabs_v1 includes device-bandwidth profiling to classify infected systems by throughput, apparently for service-tiering purposes in a commercial botnet-for-hire model. The malware also contains a killer component to remove competing malware from infected devices. It notably lacks persistence and instead appears to rely on repeated reinfection through the same exposed remote-management pathway. Overall, the actor demonstrates greater sophistication than a basic Mirai fork operator, but there is no high-confidence evidence tying Tadashi to a specific country, state sponsor, or broader intrusion cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
32 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.