A global cybercriminal campaign, dubbed ShadowRay 2.0, is actively exploiting a critical unpatched vulnerability (CVE-2023-48022) in the open-source Ray distributed computing framework, which is widely used for AI workloads. Attackers, tracked as IronErn440, are leveraging the Ray dashboard API to achieve unauthenticated remote code execution, allowing them to hijack exposed Ray clusters and convert them into a self-replicating botnet. This botnet is used for cryptocurrency mining, data and credential theft, and launching distributed denial-of-service (DDoS) attacks. The campaign represents a significant evolution from previous ShadowRay attacks, with new techniques and AI-generated payloads observed, and is believed to have been active since at least September 2024.
Despite the severity of the vulnerability, which carries a CVSS score of 9.8, no patch has been issued, as the original vendor, Anyscale, maintains Ray is intended for use in strictly controlled environments. The attack surface has grown dramatically, with over 200,000 Ray servers now exposed to the internet, many belonging to startups, research labs, and cloud-hosted AI environments. The attackers have demonstrated advanced evasion tactics, such as limiting CPU usage and disguising malicious processes, and have migrated their payload delivery infrastructure from GitLab to GitHub. The Ray project has since been transferred to the Linux Foundation's PyTorch Foundation, but the vulnerability remains unaddressed, leaving a large number of systems at risk of compromise and abuse for illicit cryptomining and other malicious activities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Oligo disclosed ShadowRay 2.0 as a global campaign exploiting CVE-2023-48022 against more than 230,000 internet-reachable Ray servers. The firm attributed the activity to a threat actor it tracks as IronErn440 and said the malware appears AI/LLM-generated based on code structure and comments.
After the GitLab disruption, the operators moved payload delivery to GitHub and continued the campaign. Oligo says this new wave began on November 17, 2025, and persisted despite account takedowns, indicating resilience and likely automation.
One recent wave of the campaign relied on GitLab to host or deliver payloads until the infrastructure was removed. Oligo says this GitLab-based phase ended on November 5, 2025.
During the campaign, the operator Oligo tracks as IronErn440 used interact.sh to discover exploitable Ray dashboard instances at scale. The discovered systems were then used for cryptomining, lateral movement, data theft, credential theft, and DDoS capabilities.
Attackers began actively exploiting internet-facing Ray clusters in a campaign Oligo says has been active since at least September 2024. The operation abused the unauthenticated Ray Jobs API to execute payloads, spread across nodes, and build a self-propagating botnet.
Oligo previously reported late-2023 exploitation activity against exposed Ray environments under the ShadowRay name, establishing the precursor to the later ShadowRay 2.0 campaign. This earlier activity was later described as less advanced than the 2024-2025 operation.
A critical exposure in Ray's dashboard and unauthenticated Jobs API, tracked as CVE-2023-48022, became known as enabling remote code execution on internet-exposed Ray clusters. The issue remained unfixed because Ray was intended for trusted network environments rather than public exposure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcesecurityonline.info
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.