216.73.216.6

ShadowRay 2.0: Active Global Campaign Hijacks Ray AI Infrastructure Into Self-Propagating Botnet

· Published 19/11/2025 04:25 · Modified 19/11/2025 08:54

Export JSON

Essential information

Published
19/11/2025 04:25
Modified
19/11/2025 08:54
Tags
2025-11-19 CVE-2023-48022 ai infrastructure botnet cryptojacking data exfiltration ddos devops ray framework self-propagation sockstress xmrig
Related entities
1 intrusion sets (apt), 19 techniques (mitre), 2 malware

Description

A global hacking campaign dubbed ShadowRay 2.0 has been discovered, exploiting a vulnerability in the Ray AI framework to seize control of computing clusters and create a self-replicating . The attackers use GitLab and GitHub for payload delivery, leveraging AI-generated code to adapt their methods. The campaign has evolved from simple to a sophisticated multi-purpose capable of attacks and . The operation targets exposed Ray clusters worldwide, utilizing -style infrastructure for real-time malware updates. This campaign highlights the growing attack surface in AI workloads and the risks associated with disputed vulnerabilities.

External references