logo

Cryptomining Campaign Exploiting Exposed Ray AI Infrastructure (Campaign)

ID: 23fcbedb-e253-520d-9eee-b1defacef1e3

STIX ID: report--23fcbedb-e253-520d-9eee-b1defacef1e3

Feed Name: Wiz Cloud Threat Landscape

Threat Score
78/100

Date Published: 2025-11-19

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

ShadowRay 2.0 is an active, global cryptomining campaign that targets Ray clusters with unauthenticated dashboards/Jobs APIs (abusing behavior tracked as CVE-2023-48022). Attackers discover exposed instances via out-of-band callbacks, submit multi-stage Bash/Python Ray jobs to achieve remote code execution, use NodeAffinitySchedulingStrategy to push malicious jobs laterally across nodes, and deploy GPU-optimized miners (XMRig, Rigel) with process masquerading and resource-throttling to avoid detection. The campaign also installs persistent cron/systemd tasks, adds SSH backdoors, exfiltrates MySQL credentials, cloud tokens, models and datasets, kills competing miners, blocks rival pools, and repurposes compromised clusters to scan and infect new Ray instances, effectively operating like a worm.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.