Frequency
4
occurrences
First Seen
November 18, 2025
Last Seen
August 6, 2026
Related Threat Clusters
-
ShadowRay 2.0 Campaign: AI-Driven Botnet Exploits Open-Source Vulnerability
Oligo Security has identified the ShadowRay 2.0 campaign, an active global hacking operation exploiting CVE-2023-48022, a flaw in the Ray AI framework. Attackers, identified as IronErn440, have created a…
3 articles · Updated August 5, 2026 -
ShadowRay 2.0 Campaign Exploits Ray Clusters for Crypto Mining
A global campaign named ShadowRay 2.0 is targeting exposed Ray clusters, exploiting the unpatched CVE-2023-48022 vulnerability. The attacks, attributed to a threat actor known as IronErn440, have been active since at…
8 articles · Updated November 18, 2025 -
ShadowRay 2.0 Campaign Targets Vulnerable Ray Clusters for Cryptomining
The ShadowRay 2.0 campaign exploits a critical vulnerability (CVE-2023-48022) in the Ray open-source framework, allowing attackers to hijack exposed Ray clusters for cryptomining, data theft, and DDoS attacks. Oligo…
6 articles · Updated November 20, 2025
Recent Intelligence Reports
- investigation into the ShadowRay 2.0 campaign — www.oligo.security · August 6, 2026
- Open-source software’s archenemy TeamPCP goes back further than anyone thought — Cyberscoop · August 5, 2026
- Self-replicating botnet attacks Ray clusters — Theregister · November 19, 2025
- Self — Theregister · November 18, 2025