ShadowRay 2.0, also known as IronErn, is a campaign linked to the cybercrime actor TeamPCP. It emerged in the second half of 2025 and is associated with the compromise of exposed Ray-based artificial intelligence infrastructure, which was converted into a self-propagating botnet used for cryptocurrency mining. The operation reflects TeamPCP’s broader pattern of targeting internet-facing cloud-native services and abusing known vulnerabilities for automated, wormable initial access and propagation. The campaign is part of a wider TeamPCP activity cluster that has targeted exposed infrastructure across technologies including Ray, Docker, Redis, and React, and later expanded into software supply chain compromises. Reporting links ShadowRay 2.0 to TeamPCP through overlapping operational infrastructure, malware staging patterns, backend systems, platform identities, and command-and-control tradecraft. TeamPCP has also been associated with credential theft and sensitive-data extraction in other operations, large-scale compromise of developer environments through poisoned open-source packages, and the use of compromised systems for scanning, proxying, cryptocurrency mining, extortion, and ransomware deployment. Within this cluster, TeamPCP has demonstrated capabilities spanning initial access, persistence, reconnaissance, scanning, exfiltration, defense evasion, and post-exploitation. Later malware evolution tied to the same actor included Kubernetes-focused tooling that combined propagation and persistence with destructive wiper-like behavior, including selective deployment of different payloads based on victim environment characteristics. ShadowRay 2.0 itself is best characterized as a cloud and AI infrastructure hijacking operation centered on self-spreading botnet formation and cryptomining.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign linked operationally to TeamPCP that hijacked AI infrastructure and turned it into a self-propagating botnet.
Operates a cryptomining botnet exploiting Ray's AI framework authentication flaw, building a global botnet for cryptomining, DDoS, and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.