• News/
  • https://www.bleepingcomputer.com/news/security/new-shadowray-attacks-convert-ray-clusters-into-crypto-miners/

New ShadowRay attacks convert Ray clusters into crypto miners

BleepingComputer
·
Bill Toulas
·
Published Nov 18, 2025
·
Updated

A global campaign dubbed ShadowRay 2.0 hijacks exposed Ray Clusters by exploiting an old code execution flaw to turn them into a self-propagating cryptomining botnet. Developed by Anyscale, the Ray open-source framework allows building and scaling AI and Python applications in a distributed computing ecosystem organized in clusters, or head nodes. According to researchers at runtime security company Oligo, a threat actor they track as IronErn440 is using AI-generated payloads to compromise vulnerable Ray infrastructure that is reachable over the public internet. They say that the malicious activity goes beyond cryptocurrency mining, and in some cases, it includes data and credentials theft, as well as deploying distributed denial-of-service (DDoS) attacks. ShadowRay 2.0 is the continuation of another ShadowRay campaign, also exposed by Oligo, which ran between September 2023 and March 2024. Oligo researchers found that an old critical vulnerability tracked as CVE-2023-48022 was exploited in both campaigns. The security issue did not receive a fix as Ray was designed to run in a trusted environment described as a "strictly-controlled network environment." However, the researchers say that there are more than 230,000 Ray servers available on the internet, a huge spike from "the few thousand we observed during our initial ShadowRay discovery." In a report today, Oligo says that it observed two attack waves, one that abused GitLab for payload delivery and terminated on November ...

Read full article

Affected Software

1 affected component
Anyscale Ray
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the ShadowRay 2.0 campaign that exploits vulnerabilities in Ray clusters for crypto mining.

2

What security implications are discussed in the article?

The article highlights the risk of turning exposed Ray clusters into a self-propagating cryptomining botnet due to an old code execution flaw.

3

What products or software are affected?

The affected software mentioned in the article is Anyscale Ray.

4

Who developed the framework that is being exploited in the ShadowRay attacks?

The Ray open-source framework, which is exploited in the attacks, is developed by Anyscale.

5

What method do the attackers use to compromise Ray clusters?

Attackers exploit an old code execution flaw to hijack Ray clusters and convert them into cryptominers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203