Promote Your Product
Got a product, service, or story to share? Promote it directly to our active community and boost your brand today.
Create an Ad
Publish Bulk Blog Posts
Boost Your Reach! 📝
Have articles, guest posts, or bulk stories to publish? Send your content directly to our editorial team and feature on our platform.
Email Us Your PostsShadowRay 2.0: AI-Powered Cyberattack Exposed
ShadowRay 2.0 Cyberattack
A sophisticated cyber operation known as ShadowRay 2.0 is actively compromising publicly accessible Ray clusters through the exploitation of a previously disclosed code execution vulnerability, transforming these systems into a self-replicating cryptocurrency mining network.
Ray, an open-source framework created by Anyscale, enables developers to construct and expand AI and Python-based applications across distributed computing environments structured as clusters or head nodes.
Security analysts at Oligo, a runtime security firm, have identified a malicious actor designated as IronErn440 who is leveraging artificially intelligence-generated attack code to breach vulnerable Ray infrastructure exposed to the public internet.
The researchers emphasize that these intrusions extend far beyond simple cryptocurrency mining operations, encompassing activities such as credential harvesting, data exfiltration, and the deployment of distributed denial-of-service (DDoS) capabilities.
This latest ShadowRay 2.0 operation represents a continuation of an earlier ShadowRay offensive, which Oligo previously documented as occurring between September 2023 and March 2024.
Oligo's investigation revealed that both attack campaigns exploited CVE-2023-48022, a critical security flaw that remains unpatched. The vulnerability was left unaddressed because Ray's architecture was originally intended for deployment within trusted environments characterized as "strictly-controlled network environments."
Despite this design assumption, researchers have discovered an alarming reality: over 230,000 Ray servers are currently accessible via the internet, representing a dramatic escalation from "the few thousand we observed during our initial ShadowRay discovery."
In their latest analysis published today, Oligo documented two distinct attack phases. The first wave utilized GitLab infrastructure for malicious payload distribution and concluded on November 5, while the second wave, which began on November 17 and remains active, exploits GitHub for the same purpose.
Security researchers at Oligo have determined that malicious code deployed during these intrusions bears telltale signs of artificial intelligence assistance in its creation. The determination stems from examining how the code was structured, reviewing embedded annotations, and studying the methods used for managing errors.
When analysts decoded one particular malicious package, they discovered it included documentation strings alongside unnecessary echo commands. These characteristics point strongly toward the involvement of large language models in producing the attack code.
The presence of such elements provides compelling evidence that threat actors are now leveraging AI-powered tools to streamline the development of their exploitation frameworks and cryptocurrency mining payloads.Attackers are exploiting CVE-2023-48022 to submit malicious tasks through Ray's unauthenticated jobs API. These tasks execute multi-stage bash and python payloads, hijacking the platform's orchestration to deploy malware across every node in a cluster. This method enables the threat to spread autonomously from one compromised cluster to another. The deployed crypto-mining module itself exhibits signs of being AI-generated. It performs reconnaissance, checking available CPU and GPU resources and the level of system access. Code within the payload reveals the attacker's preference for systems with at least eight cores and root privileges, humorously labeling such a setup "a very good boy." For the mining operation, the attackers employ XMRig to mine Monero. To avoid triggering immediate alerts, the malware is configured to use only 60% of the available processing power. The miners are strategically placed in deceptive file locations and masquerade under innocuous process names, such as 'dns-filter,' to evade detection. Persistence is ensured through the creation of cron jobs and modifications to systemd. A notable aspect of this campaign is the attacker's territorial behavior on compromised infrastructure. They actively seek out and terminate any rival cryptocurrency mining scripts already running on the cluster. Furthermore, they block connections to other mining pools by manipulating the `/etc/hosts` file and configuring iptables firewall rules. , ensuring you have the correct version compatible with your operating system. Once installed, launch the application and enable the App Mode feature, which provides enhanced access and flexibility for browsing. Next, browse through the available server locations and select a region where the desired content is accessible. Connecting to this server will mask your real IP address and make it appear as though you are browsing from the selected region. Finally, start browsing your favorite adult sites with complete privacy and unrestricted access, knowing your identity remains protected throughout the process.
- Art
- Causes
- Crafts
- Dance
- Drinks
- Film
- Fitness
- Food
- Jogos
- Gardening
- Health
- Início
- Literature
- Music
- Networking
- Outro
- Party
- Religion
- Shopping
- Sports
- Theater
- Wellness