Skip to content
ShadowRay 2.0 Campaign Exploits Ray Clusters for Crypto Mining

ShadowRay 2.0 Campaign Exploits Ray Clusters for Crypto Mining

First seen 18 Nov 2025, 22:15 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A global campaign named ShadowRay 2.0 is targeting exposed Ray clusters, exploiting the unpatched CVE-2023-48022 vulnerability. The attacks, attributed to a threat actor known as IronErn440, have been active since at least September 2024, converting compromised systems into a self-replicating botnet for cryptocurrency mining and data theft.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 188d ago How this analysis works

More articles in this cluster (8)

Following this threat?

Track IronErn440, ShadowRay 2.0 and AWS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed