Ray Clusters Hijacked and Turned Into Crypto Miners by Shadowy New Botnet

Ray Clusters Hijacked and Turned Into Crypto Miners by Shadowy New Botnet

TechRadar
TechRadarNov 19, 2025

Why It Matters

The exploitation turns legitimate high‑performance computing resources into profit‑driving crypto miners and attack platforms, inflating operational costs and exposing sensitive data, while highlighting the risks of unpatched open‑source infrastructure in cloud environments.

Summary

Cybersecurity firm Oligo has identified a new wave of attacks exploiting a critical flaw in Ray 2.6.3 and 2.8.0 that allows unauthenticated code execution via the job‑submission API. Threat actors, dubbed IronErn440, have been using AI‑generated payloads to infiltrate more than 230,000 internet‑exposed Ray clusters since September 2023, deploying XMRig cryptominers that run at up to 60% CPU to evade detection. The campaign also includes data exfiltration and DDoS capabilities, marking the second major abuse of this vulnerability. Anyscale, the maintainer of Ray, has not patched the flaw, leaving users responsible for securing their deployments.

Ray clusters hijacked and turned into crypto miners by shadowy new botnet

Comments

Want to join the conversation?

Loading comments...