www.oligo.security
ShadowRay 2.0 Campaign: AI-Driven Botnet Exploits Open-Source Vulnerability
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Oligo Security has identified the ShadowRay 2.0 campaign, an active global hacking operation exploiting CVE-2023-48022, a flaw in the Ray AI framework. Attackers, identified as IronErn440, have created a self-propagating botnet by hijacking AI infrastructure, affecting over 230,000 Ray servers worldwide. The campaign utilizes AI-generated payloads to adapt and evolve rapidly, allowing for efficient exploitation of computing clusters. The attackers initially used GitLab for malware delivery but have since migrated to GitHub. Evidence suggests that this operation has been active since September 2024, with significant implications for the security of AI systems. The campaign's sophistication includes evading detection by limiting CPU usage and disguising malicious processes. This represents a notable evolution in cyber threats, combining AI with traditional attack vectors.
Key Points: • ShadowRay 2.0 exploits CVE-2023-48022 in the Ray AI framework, affecting over 230,000 servers. • Attackers have transitioned from GitLab to GitHub for malware distribution, indicating adaptability. • The campaign utilizes AI-generated payloads for rapid evolution and adaptation during attacks.