ShadowRay 2.0 Campaign Targets Vulnerable Ray Clusters for Cryptomining

ShadowRay 2.0 Campaign Targets Vulnerable Ray Clusters for Cryptomining

First seen 2 Dec 2025, 18:33 UTC BleepingcomputerTheregisterWizEsecurityplanetScworld 84% similarity 25.1

Article Content

Browse articles
ThreatCluster

The ShadowRay 2.0 campaign exploits a critical vulnerability (CVE-2023-48022) in the Ray open-source framework, allowing attackers to hijack exposed Ray clusters for cryptomining, data theft, and DDoS attacks. Oligo Security researchers identified this ongoing global threat, which has been active since at least September 2024, and discovered that attackers are using AI-generated payloads to compromise vulnerable systems.

ThreatCluster AI How this analysis works

Community

Browse all →