Vulnerability Management

Internet-exposed Ray clusters targeted by self-replicating botnet

botnet bot-net computer virus

Widely used open-source artificial intelligence framework Ray is having its internet-exposed clusters vulnerable to the unpatched critical flaw, tracked as CVE-2023-48022, targeted with a self-propagating botnet facilitating cryptocurrency mining, data exfiltration, and distributed denial-of-service intrusions as part of the ongoing ShadowRay 2.0 campaign, according to The Register.

Numerous organizations, particularly those with massive clusters and expensive GPU environments, have been targeted by the IronErn440 threat operation in intrusions that enabled at-scale discovery of targets via callbacks, a report from Oligo Security revealed. Unauthenticated Ray job submission APIs were then leveraged by attackers to enable cryptomining, lateral network movement, and further machine compromise for subsequent DDoS attacks.

"In several instances, the attackers also accessed proprietary company assets, including AI models, datasets, and application source code, cloud credentials, database credentials, and access to retained user data from production environments," said researchers, who have attributed the campaign's accelerated recovery and stealth to automation.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds