www.oligo.security ShadowRay 2.0 Campaign: AI-Driven Botnet Exploits Open-Source Vulnerability
Article Content
- •ShadowRay 2.0 exploits CVE-2023-48022 in the Ray AI framework, affecting over 230,000 servers.
- •Attackers have transitioned from GitLab to GitHub for malware distribution, indicating adaptability.
- •The campaign utilizes AI-generated payloads for rapid evolution and adaptation during attacks.
Oligo Security has identified the ShadowRay 2.0 campaign, an active global hacking operation exploiting CVE-2023-48022, a flaw in the Ray AI framework. Attackers, identified as IronErn440, have created a self-propagating botnet by hijacking AI infrastructure, affecting over 230,000 Ray servers worldwide. The campaign utilizes AI-generated payloads to adapt and evolve rapidly, allowing for efficient exploitation of computing clusters. The attackers initially used GitLab for malware delivery but have since migrated to GitHub. Evidence suggests that this operation has been active since September 2024, with significant implications for the security of AI systems. The campaign's sophistication includes evading detection by limiting CPU usage and disguising malicious processes. This represents a notable evolution in cyber threats, combining AI with traditional attack vectors.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track TeamPCP, ShadowRay 2.0 and AWS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
AI Infrastructure Under Siege: Session Hijacking and Exploits Surge Recent cybersecurity incidents have targeted AI platforms and enterprise systems, with significant exploits reported. Notable vulnerabilities include the PaperCut remote code execution flaw (CVE-2026-65105) being actively exploited. Attackers are hijacking authenticated browser sessions for AI services like Claude…
AI Safety Concerns and Cybersecurity Threats Surge Amid Exploitation Risks This week, AI safety researchers at Anthropic warned of a potential 10% chance that advanced AI could lead to human extinction within the decade. The concerns were amplified by the resignation of Jacob Coxon, who cautioned that leading AI firms like OpenAI and Anthropic are racing to develop uncontrollable superhuman…