ShadowRay 2.0 is a self-propagating cryptomining malware campaign targeting internet-exposed Ray clusters used for distributed AI and Python workloads. It exploits CVE-2023-48022, an unauthenticated remote code execution weakness in exposed Ray dashboard and job submission functionality, to seize control of cluster head nodes and abuse Ray orchestration features to execute malicious jobs across additional nodes, including internal non-internet-facing systems. The operation has been associated with activity tracked as IronErn440 and later linked to the broader operational ecosystem associated with TeamPCP and TA-NATALSTATUS.
The malware delivers multi-stage Bash and Python payloads, establishes remote interactive access through reverse shells, and persists through recurring scheduled reinfection mechanisms, including cron and in some reporting systemd changes. It deploys XMRig to mine cryptocurrency, preferentially targeting high-performance environments such as NVIDIA GPU-equipped clusters, throttles resource consumption to reduce detection, disguises processes as benign system activity, and kills competing miners. ShadowRay 2.0 also uses compromised Ray infrastructure to spread laterally within clusters and to scan for and compromise other exposed Ray environments, giving it worm-like behavior.
Beyond cryptomining, ShadowRay 2.0 has been observed supporting post-compromise theft of credentials and sensitive workload data, including cloud, database, source code, model, and dataset access present on infected clusters. Compromised systems have also been used to launch DDoS activity via Sockstress, indicating the botnet is multi-purpose rather than purely monetized through mining. Payload hosting and update infrastructure shifted between code-hosting platforms after takedowns, demonstrating operational resilience and automation. The campaign has been active since at least September 2024 as an evolution of earlier ShadowRay activity observed from late 2023 into early 2024, and it has targeted exposed Ray deployments globally at significant scale.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
A global campaign dubbed ShadowRay 2.0 hijacks exposed Ray Clusters by exploiting an old code execution flaw to turn them into a self-propagating cryptomining botnet.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The firm also assessed that TeamPCP ran ShadowRay 2.0, the campaign it documented in November 2025 against exposed Ray clusters, which it had attributed at the time to an actor called IronErn440.
The firm also assessed that TeamPCP ran ShadowRay 2.0, the campaign it documented in November 2025 against exposed Ray clusters, which it had attributed at the time to an actor called IronErn440.
The firm also assessed that TeamPCP ran ShadowRay 2.0, the campaign it documented in November 2025 against exposed Ray clusters, which it had attributed at the time to an actor called IronErn440.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An operation against exposed Ray clusters linked by shared infrastructure and deployment paths to TeamPCP activity; later-stage Kubernetes payloads included a destructive branch that deleted filesystems and rebooted machines when systems were set to the Iran timezone.
Self-replicating cryptomining botnet targeting Ray clusters with NVIDIA GPUs; exploits an unpatched Ray framework flaw.
ShadowRay 2.0 is a self-propagating botnet and cryptomining malware campaign that targets exposed Ray framework clusters. It hijacks AI infrastructure for cryptomining, data theft, and further botnet expansion, leveraging a critical RCE vulnerability (CVE-2023-48022) in Ray. The malware also steals credentials, cloud tokens, proprietary AI models, and source code.
ShadowRay 2.0 is a botnet malware that hijacks AI systems, turning them into self-propagating bots in a global campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.