Ray clusters hijacked and transformed into crypto miners by a new dark botnet


  • Ray clusters remain vulnerable to remote code execution via unauthenticated Jobs API
  • Threat group “IronErn440” exploits a flaw in AI-generated payloads and deploys the XMRig cryptojacker.
  • More than 230,000 Ray servers are exposed online, compared to a few thousand in 2023

Ray clusters, still vulnerable to a critical severity flaw discovered years ago, are being used for cryptocurrency mining, data exfiltration and even distributed denial of service (DDoS) attacks, experts have warned.

Cybersecurity researchers Oligo say this is the second major campaign to exploit this same flaw.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top