ShadowRay 2.0 Campaign: AI-Driven Botnet Exploits Open-Source Vulnerability

ShadowRay 2.0 Campaign: AI-Driven Botnet Exploits Open-Source Vulnerability

First seen 5 Aug 2026, 13:26 UTC Cyberscoopwww.oligo.security 75% similarity 66.6

Article Content

Browse articles
ThreatCluster

Oligo Security has identified the ShadowRay 2.0 campaign, an active global hacking operation exploiting CVE-2023-48022, a flaw in the Ray AI framework. Attackers, identified as IronErn440, have created a self-propagating botnet by hijacking AI infrastructure, affecting over 230,000 Ray servers worldwide. The campaign utilizes AI-generated payloads to adapt and evolve rapidly, allowing for efficient exploitation of computing clusters. The attackers initially used GitLab for malware delivery but have since migrated to GitHub. Evidence suggests that this operation has been active since September 2024, with significant implications for the security of AI systems. The campaign's sophistication includes evading detection by limiting CPU usage and disguising malicious processes. This represents a notable evolution in cyber threats, combining AI with traditional attack vectors.

Key Points: • ShadowRay 2.0 exploits CVE-2023-48022 in the Ray AI framework, affecting over 230,000 servers. • Attackers have transitioned from GitLab to GitHub for malware distribution, indicating adaptability. • The campaign utilizes AI-generated payloads for rapid evolution and adaptation during attacks.

ThreatCluster AI How this analysis works

Timeline

2023-11-28
CVE-2023-48022 published
A vulnerability in the Ray AI framework was disclosed, allowing for potential exploitation.
Oligo Security
2024-01-10
First public PoC for CVE-2023-48022
The first proof of concept for the vulnerability was released, increasing the risk of exploitation.
Oligo Security
2024-09-01
ShadowRay 2.0 campaign identified
Oligo Security researchers discovered the ongoing ShadowRay 2.0 campaign leveraging the Ray vulnerability.
Oligo Security
2025-11-05
Attackers removed from GitLab
Oligo reported the malicious accounts to GitLab, leading to their removal from the platform.
Oligo Security
2025-11-10
Attackers migrate to GitHub
Following their removal from GitLab, attackers created new accounts on GitHub to continue their campaign.
Oligo Security
2026-08-05
Ongoing ShadowRay 2.0 campaign reported
The ShadowRay 2.0 campaign remains active, with significant global implications for AI infrastructure.
Oligo Security

Community

Browse all →

Tracked Entities in This Story