logo

New ShadowRay attacks convert Ray clusters into crypto miners

ID: e6f9ecde-e141-543b-b878-04b19fcbd3f7

STIX ID: report--e6f9ecde-e141-543b-b878-04b19fcbd3f7

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-11-18

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

Oligo Security reports an active ShadowRay 2.0 campaign in which threat actor "IronErn440" exploits CVE-2023-48022 to hijack internet-exposed Ray clusters, deploying LLM-generated multi-stage payloads that install XMRig-based Monero miners, establish reverse shells for data/credential theft, and enable DDoS and lateral cluster-to-cluster propagation; the vulnerability remains unfixed, and researchers observed large-scale exposure (≈230,000 Ray servers) with ongoing GitHub/GitLab-based delivery and persistence mechanisms such as cron and systemd.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.