logo

ShadowRay 2.0 Turns AI Clusters into Crypto Botnets

ID: ae528e5c-4025-5693-a1c7-6ce48e4a112d

STIX ID: report--ae528e5c-4025-5693-a1c7-6ce48e4a112d

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-11-24

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Oligo Security describes an active global campaign called ShadowRay 2.0 in which threat actors (IronErn440) exploit a disputed critical RCE in the Ray framework (Jobs API / exposed dashboards) to take over AI clusters, deploy cryptominers (XMRig, Rigel), exfiltrate credentials and AI models, and autonomously propagate across exposed Ray environments via GitLab/GitHub-hosted, AI-generated payloads; the report warns of widespread exposure (≈230,000 Ray instances) and recommends proper configuration and authorization layers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.