New ShadowRay attacks convert Ray clusters into crypto miners
ID: e6f9ecde-e141-543b-b878-04b19fcbd3f7
STIX ID: report--e6f9ecde-e141-543b-b878-04b19fcbd3f7
Feed Name: Bleeping Computer
Oligo Security reports an active ShadowRay 2.0 campaign in which threat actor "IronErn440" exploits CVE-2023-48022 to hijack internet-exposed Ray clusters, deploying LLM-generated multi-stage payloads that install XMRig-based Monero miners, establish reverse shells for data/credential theft, and enable DDoS and lateral cluster-to-cluster propagation; the vulnerability remains unfixed, and researchers observed large-scale exposure (≈230,000 Ray servers) with ongoing GitHub/GitLab-based delivery and persistence mechanisms such as cron and systemd.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
