ShadowRay 2.0 Campaign Exploits Ray Clusters for Crypto Mining

ShadowRay 2.0 Campaign Exploits Ray Clusters for Crypto Mining

First seen 18 Nov 2025, 22:15 UTC BleepingcomputerTheregisterWizGbhackersCybersecuritynews+2 97% similarity 41.7

Article Content

Browse articles
ThreatCluster

A global campaign named ShadowRay 2.0 is targeting exposed Ray clusters, exploiting the unpatched CVE-2023-48022 vulnerability. The attacks, attributed to a threat actor known as IronErn440, have been active since at least September 2024, converting compromised systems into a self-replicating botnet for cryptocurrency mining and data theft.

ThreatCluster AI How this analysis works

Community

Browse all →