Ray clusters hijacked and turned into crypto miners by shadowy new botnet

  • Ray clusters remain vulnerable to remote code execution via unauthenticated Jobs API
  • Threat group “IronErn440” exploits flaw with AI-generated payloads, deploying XMRig cryptojacker
  • Over 230,000 Ray servers are exposed online, up from a few thousand in 2023

Ray clusters, still vulnerable to a critical severity flaw discovered years ago, are being used for cryptocurrency mining, data exfiltration, and even Distributed Denial of Service (DDoS) attacks, experts have warned.

Cybersecurity researchers Oligo claim this is the second major campaign to leverage this same flaw.

Ray is an open source network that helps run Python programs faster by decentralizing and distributing the work across multiple machines. Its clusters are groups of computers – one head node and multiple worker nodes – that work together to run Ray tasks and workloads in a distributed and coordinated way.

Official IdentityForce® | Identity Theft Protection – save up to 68% annually

Many people don’t know how to protect their ID. Don’t be one of them. Get your ID Action Plan here. Get a personalized step-by-step Action Plan & ID Safety Score based on YOUR dark web hits.View Deal

Deploying and hiding XMRig

Back in 2023, it was discovered that Ray 2.6.3 and 2.8.0 carried a vulnerability that allowed a remote attacker to execute arbitrary code via the job submission API. However Anyscale, the company behind the product, did not fix it since it is designed to run in a “strictly-controlled network environment”.

In other words – it’s up to the users to secure their infrastructure and make sure the flaw does not get abused.

But abused, it was. First, between September 2023 and March 2024, and today. Oligo says that threat actors tracked as “IronErn440” are now using AI-generated payloads to infiltrate vulnerable clusters. By leveraging the bug, the attackers submit jobs to unauthenticated Jobs API, running multi-stage Bash and Python payloads hosted on GitHub and GitLab.

These payloads deploy malware to the devices – usually the infamous XMRig cryptojacker. While this cryptojacker is usually easily spotted (since it takes up 100% of the device’s processing power and renders it useless for pretty much anything else), the attackers tried to work around this issue by locking it to 60% of processing power.

Today, there are more than 230,000 Ray servers exposed to the internet, the researchers warned, saying that their numbers grew significantly compared to just “a few thousand” that were available when the vulnerability was first discovered.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

OpenAI rolls out GPT-5.6 after government greenlight — and announces ‘ChatGPT Work’

About two weeks after OpenAI's GPT-5.6 was caught up in regulatory drama - rolled out only to government-approved organizations during a "limited preview" period...

Microsoft’s patch Tuesdays are about to get bigger

Windows 11 updates could soon include fixes for more security issues at once. Microsoft said in a blog post on Thursday that it's now...

Google’s Nest Thermostat has hit its best price of the year

Google’s 2020 Nest Thermostat is $50 off. | Photo by Dan Seifert / The Verge If you’re looking for a relatively affordable way to cut...

Google will now tell you if an ad was made with AI

You can see if ads on Google Search, Google Discover, and YouTube were made or edited using AI from a new section in Google's...

Samsung boosts Galaxy S26 production on the fears of more expensive sequels

As RAMageddon rages on, Samsung is reportedly boosting production of its existing Galaxy S26 series to meet growing demand as customers hope to buy...

Google asks for Gemini app feedback & details top 10 requests

Yesterday, Google’s Josh Woodward asked for what fixes Gemini app users want. The Gemini lead today identified the top 10 requests and Google’s progress. Read...

Today’s Android app deals and freebies: Outliver, Dealer’s Life, Zero Stress King, more

Your Thursday lineup of the best Android game and app deals is now ready to roll, including titles like Outliver: Tribulation, Aces of the...

Google might rebrand Pixel Magic Cue as Gemini ‘Proactive Assistance’ 

With the Pixel 10 series last year, Google introduced Magic Cue to “proactively surface relevant info and suggest helpful actions when you need them.”...

FL Studio 2026 turns its AI chatbot into your assistant engineer

Gopher can’t play the piano for you, but it can bury it in the mix. | Image: Image Line Last year, Image Line introduced Gopher...

Character.AI wants a piece of the microdrama pie

Character.AI's plan to become more than just an LLM-powered chatbot platform is going beyond interactive books, comics, and audio dramas. Today, the company announced...