Mirai-Based xlabs_v1 Botnet Exploits ADB to Hijack IoT Devices for DDoS Attacks

2026-05-07T01:24:13Z80b8a54c960e17924b3a9d9e7a21139bb05538084639b69dc28db62ad416bb2c
ADBAI agent governanceApache HTTP/2CISA KEVDAEMON ToolsDDoSIoT botnetLinux LPEMOVEitMetInfo CMSMicrosoft TeamsMiraiMuddyWaterOAuth token riskPAN-OSRMM abuseScarCruftSilver FoxTreillix breachWeaver E-cologycredential theftphishingransomwaresupply chain compromise

What happened

A broad set of active threats and high-severity vulnerabilities were reported: a Mirai-derived xlabs_v1 botnet is exploiting exposed Android Debug Bridge (ADB) endpoints to recruit IoT devices for DDoS; nation-state and crimeware actors (MuddyWater, ScarCruft, Silver Fox) are using supply-chain trojans, phishing (including Microsoft Teams), and new malware families for credential theft, ransomware false-flagging, and espionage; multiple critical remote code execution and escalation flaws are being actively exploited or patched (notably in Palo Alto PAN-OS, Apache HTTP/2, MetInfo CMS, Weaver E‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
80b8a54c960e17924b3a9d9e7a21139bb05538084639b69dc28db62ad416bb2c
Enrichment time
2026-05-07T01:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.