Bleepingcomputer
ShadowRay 2.0 Campaign Targets Vulnerable Ray Clusters for Cryptomining
First seen 2 Dec 2025, 18:33 UTC
•



•84% similarity
•25.1
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
The ShadowRay 2.0 campaign exploits a critical vulnerability (CVE-2023-48022) in the Ray open-source framework, allowing attackers to hijack exposed Ray clusters for cryptomining, data theft, and DDoS attacks. Oligo Security researchers identified this ongoing global threat, which has been active since at least September 2024, and discovered that attackers are using AI-generated payloads to compromise vulnerable systems.
ThreatCluster AI
How this analysis works