ShadowRay 2.0 is a self-propagating cryptomining botnet campaign targeting internet-exposed Ray clusters, particularly GPU-equipped environments used for distributed AI and machine learning workloads. The operation exploits Ray’s unauthenticated job submission and orchestration features, most notably the long-reported missing-authentication issue tracked as CVE-2023-48022, to achieve remote code execution on exposed clusters and spread across additional nodes and other reachable Ray environments.
Once deployed, ShadowRay 2.0 executes multi-stage Bash and Python payloads, performs reconnaissance, and uses Ray scheduling and orchestration mechanisms to run across cluster nodes, including non-internet-facing systems reachable from the compromised head node. The malware installs XMRig for illicit cryptocurrency mining, checks available CPU and GPU resources, throttles resource consumption to reduce visibility, kills competing miners, and disguises malicious processes to evade detection. Persistence has been observed through recurring scheduled reinfection and system service modification, enabling the operators to refresh payloads and maintain control over compromised infrastructure.
Beyond cryptomining, ShadowRay 2.0 has been associated with reverse-shell access for interactive post-compromise control, theft of credentials and sensitive workload data resident on compromised clusters, lateral movement within Ray-managed environments, and deployment of Sockstress for TCP state exhaustion attacks, indicating DDoS capability. The campaign has used code-hosting platforms for payload staging and updates and has shown resilience by shifting infrastructure after takedowns. Researchers have linked the activity to an operator tracked as IronErn440 and later assessed continuity with TeamPCP, suggesting ShadowRay 2.0 is part of a broader operational ecosystem rather than an isolated cryptojacking effort. The campaign has been active since at least 2024 and has targeted exposed Ray infrastructure globally.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The vulnerability in question relates to CVE-2025-62593 (CVSS score: 9.4), which can result in remote code execution via web browsers like Mozilla Firefox and Apple Safari by means of a DNS rebinding attack. | unpatched Ray instances have also been at the receiving end of cyber attacks that aim to turn infected clusters with NVIDIA GPUs into a self-replicating cryptocurrency mining botnet as part of a campaign dubbed ShadowRay 2.0
A global campaign dubbed ShadowRay 2.0 hijacks exposed Ray Clusters by exploiting an old code execution flaw to turn them into a self-propagating cryptomining botnet.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The firm also assessed that TeamPCP ran ShadowRay 2.0, the campaign it documented in November 2025 against exposed Ray clusters, which it had attributed at the time to an actor called IronErn440.
The firm also assessed that TeamPCP ran ShadowRay 2.0, the campaign it documented in November 2025 against exposed Ray clusters, which it had attributed at the time to an actor called IronErn440.
The firm also assessed that TeamPCP ran ShadowRay 2.0, the campaign it documented in November 2025 against exposed Ray clusters, which it had attributed at the time to an actor called IronErn440.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A campaign targeting unpatched Ray instances to convert NVIDIA GPU-equipped clusters into a self-replicating cryptocurrency mining botnet.
An operation against exposed Ray clusters linked by shared infrastructure and deployment paths to TeamPCP activity; later-stage Kubernetes payloads included a destructive branch that deleted filesystems and rebooted machines when systems were set to the Iran timezone.
Self-replicating cryptomining botnet targeting Ray clusters with NVIDIA GPUs; exploits an unpatched Ray framework flaw.
ShadowRay 2.0 is a self-propagating botnet and cryptomining malware campaign that targets exposed Ray framework clusters. It hijacks AI infrastructure for cryptomining, data theft, and further botnet expansion, leveraging a critical RCE vulnerability (CVE-2023-48022) in Ray. The malware also steals credentials, cloud tokens, proprietary AI models, and source code.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.