Skip to content
ShadowRay 2.0 Campaign Targets Vulnerable Ray Clusters for Cryptomining

ShadowRay 2.0 Campaign Targets Vulnerable Ray Clusters for Cryptomining

First seen 2 Dec 2025, 18:33 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

The ShadowRay 2.0 campaign exploits a critical vulnerability (CVE-2023-48022) in the Ray open-source framework, allowing attackers to hijack exposed Ray clusters for cryptomining, data theft, and DDoS attacks. Oligo Security researchers identified this ongoing global threat, which has been active since at least September 2024, and discovered that attackers are using AI-generated payloads to compromise vulnerable systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 188d ago How this analysis works

More articles in this cluster (6)

Following this threat?

Track IronErn440, ShadowRay 2.0 and Princeton University in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed