OEFE A.I CyberSecurity Scoring
OEFE
Company Information
Website:https://www.offshore-energy.biz/fossilenergy/
Employees number:None
Number of followers:269,745
NAICS:519131
Industry Type:Online Audio and Video Media
Homepage:offshore-energy.biz
OEFE Risk Score (AI oriented)
Between 750 and 799
OEFEOnline Audio and Video Media
Updated:
04/05/2026
04/05/2026
765/1000
Fair
Baa
OEFE Global Score (TPRM)
xxxx
OEFEOnline Audio and Video Media
Score locked

OEFEFair
Current Score
765Baa (FAIR)
01000
1 incidents
-16 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
766
MAY 2026
765
APRIL 2026
781
Cyber Attack
01 Apr 2026 • OEFE
Minecraft and Offshore LC: New xlabs_v1 Botnet Targets Minecraft Servers Through ADB-Exposed Android Devices
New xlabs_v1 Botnet Targets Minecraft Servers via Exposed Android ADB Ports
765
HIGH-16
MOJOFF1777912275
New xlabs_v1 Botnet Targets Minecraft Servers via Exposed Android ADB Ports
A recently discovered botnet, xlabs_v1, is exploiting Android devices with exposed Android Debug Bridge (ADB) ports to launch DDoS-for-hire attacks against Minecraft game servers. Based on the Mirai malware, this operation allows paying customers to flood servers with traffic, disrupting gameplay.
The botnet targets any internet-facing device running ADB on TCP port 5555, including Android TV boxes, smart TVs, routers, and IoT hardware with ADB enabled by default. Once compromised, the malware drops a binary into `/data/local/tmp/`, executes it, and recruits the device into a botnet fleet. A specialized RakNet flood variant is used to attack Minecraft servers, with the bot binary distributed over TCP port 25565, the default Minecraft server port.
Security researchers at Hunt.io uncovered the operation in early April 2026 while monitoring bulletproof-hosting netblocks. An exposed directory on a Netherlands-based server (176.65.139[.]44) hosted by Offshore LC (AS214472) revealed the full toolkit, including ELF binaries, infection payloads, and proxy credentials. Analysis of an unstripped development build exposed the C2 domain (xlabslover[.]lol), the operator’s handle (Tadashi), and an authentication token embedded in every bot variant.
The botnet’s infrastructure is confined to a single /24 netblock, housing the C2 server, staging host, and distribution nodes. A Monero cryptomining campaign using VLTRig was also detected on the same netblock, though its connection to xlabs_v1 remains unconfirmed.
### Infection & Evasion Tactics
Once installed, the malware employs multiple stealth techniques:
- Blocks SIGINT signals to prevent interruption.
- Erases startup arguments to hide its origin.
- Decrypts strings (ChaCha20) containing C2 details.
- Masquerades as `/bin/bash` to evade process monitoring.
- Daemonizes itself, closing I/O handles to run silently.
- Kills competing malware, including a rival bot on TCP port 24936.
- Opens a fallback listener (TCP 26721) if C2 communication fails.
- Profiles bandwidth by testing upload speeds via Speedtest servers, allowing tiered pricing for DDoS customers.
Defenders are tracking indicators of compromise, including outbound connections to xlabslover[.]lol (TCP 35342) and pool[.]hashvault[.]pro, as well as suspicious files in `/data/local/tmp/arm7`. The campaign highlights the risks of unsecured ADB ports on internet-facing devices.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
MARCH 2026
781
FEBRUARY 2026
781
JANUARY 2026
781
DECEMBER 2025
781
NOVEMBER 2025
781
OCTOBER 2025
781
SEPTEMBER 2025
781
AUGUST 2025
781
JULY 2025
781
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for OEFE ??
What was OEFE's A.I Rankiteo Cyber Score in May 2026 ??
What was OEFE's A.I Rankiteo Cyber Score in April 2026 ??
What was OEFE's A.I Rankiteo Cyber Score in March 2026 ??
What was OEFE's A.I Rankiteo Cyber Score in February 2026 ??
What was OEFE's A.I Rankiteo Cyber Score in January 2026 ??
What was OEFE's A.I Rankiteo Cyber Score in December 2025 ??
What was OEFE's A.I Rankiteo Cyber Score in November 2025 ??
What was OEFE's A.I Rankiteo Cyber Score in October 2025 ??
What was OEFE's A.I Rankiteo Cyber Score in September 2025 ??
What was OEFE's A.I Rankiteo Cyber Score in August 2025 ??
What was OEFE's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on OEFE's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with OEFE ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view OEFE's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?