Mirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacks
2026-05-07T01:24:13Z•80b8a54c960e17924b3a9d9e7a21139bb05538084639b69dc28db62ad416bb2c
ADBAI agent governanceApache HTTP/2CISA KEVDAEMON ToolsDDoSIoT botnetLinux LPEMOVEitMetInfo CMSMicrosoft TeamsMiraiMuddyWaterOAuth token riskPAN-OSRMM abuseScarCruftSilver FoxTreillix breachWeaver E-cologycredential theftphishingransomwaresupply chain compromise
What happened
A broad set of active threats and high-severity vulnerabilities were reported: a Mirai-derived xlabs_v1 botnet is exploiting exposed Android Debug Bridge (ADB) endpoints to recruit IoT devices for DDoS; nation-state and crimeware actors (MuddyWater, ScarCruft, Silver Fox) are using supply-chain trojans, phishing (including Microsoft Teams), and new malware families for credential theft, ransomware false-flagging, and espionage; multiple critical remote code execution and escalation flaws are being actively exploited or patched (notably in Palo Alto PAN-OS, Apache HTTP/2, MetInfo CMS, Weaver E‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 80b8a54c960e17924b3a9d9e7a21139bb05538084639b69dc28db62ad416bb2c
- Enrichment time
- 2026-05-07T01:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.