Ray Clusters Hijacked and Turned into Crypto Miners by Shadowy New Botnet



  • Ray clusters remain vulnerable to remote code execution via unauthenticated Jobs API
  • “IronErn440” threat group exploits flaw with AI-generated payloads and deploys XMRig cryptojacker
  • More than 230,000 Ray servers exposed online, up from just a few thousand in 2023

Experts have warned that Ray clusters, still vulnerable to a critical severity flaw discovered years ago, are being used for cryptocurrency mining, data exfiltration and even distributed denial of service (DDoS) attacks.

Cybersecurity researchers Oligo say this is the second major campaign to exploit this same flaw.



Leave a Comment

Your email address will not be published. Required fields are marked *