Sockstress is a historical socket-level attack tool used to overwhelm targets by opening large numbers of concurrent sockets, illustrating a class of resource-exhaustion DDoS primitives.
Overview
Sockstress is a historical socket-level attack tool used to overwhelm targets by opening large numbers of concurrent sockets, illustrating a class of resource-exhaustion DDoS primitives. It underscores the risk of socket- and OS-level limits being exploited and the need for mitigations such as connection management and protocol hardening. In the current threat landscape described by the provided articles, adversaries are repurposing AI infrastructure (Ray clusters) for cryptomining, highlighting a shift from classic DDoS targets to abusing compromised infrastructure for mining.
Related Threat Clusters
-
ShadowRay 2.0 Campaign Exploits Ray Clusters for Crypto Mining
A global campaign named ShadowRay 2.0 is targeting exposed Ray clusters, exploiting the unpatched CVE-2023-48022 vulnerability. The attacks, attributed to a threat actor known as IronErn440, have been active since at…
8 articles · Updated November 18, 2025 -
ShadowRay 2.0 Campaign Targets Vulnerable Ray Clusters for Cryptomining
The ShadowRay 2.0 campaign exploits a critical vulnerability (CVE-2023-48022) in the Ray open-source framework, allowing attackers to hijack exposed Ray clusters for cryptomining, data theft, and DDoS attacks. Oligo…
6 articles · Updated November 20, 2025
Recent Intelligence Reports
- Cryptomining Campaign Exploiting Exposed Ray AI Infrastructure (Campaign) — Wiz · November 19, 2025
- New ShadowRay attacks convert Ray clusters into crypto miners — Bleepingcomputer · November 18, 2025