ShadowRay

C0045

Campaign, Sep 2023 to Mar 2024.View on attack.mitre.org

About this campaign

ShadowRay was a campaign that began in late 2023 targeting the education, cryptocurrency, biopharma, and other sectors through a vulnerability (CVE-2023-48022) in the Ray AI framework named ShadowRay. According to security researchers ShadowRay was the first known instance of AI workloads being activley exploited in the wild through vulnerabilities in AI infrastructure. CVE-2023-48022, which allows access to compute resources and sensitive data for exposed instances, remains unpatched and has been disputed by the vendor as they maintain that Ray is not intended for use outside of a strictly controlled network environment.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1003.008
/etc/passwd and /etc/shadow

During ShadowRay, threat actors used `cat /etc/shadow` to steal password hashes.

T1016
System Network Configuration Discovery

During ShadowRay, threat actors invoked DNS queries from targeted machines to identify their IP addresses.

T1027.013
Encrypted/Encoded File

During ShadowRay, threat actors used Base64-encrypted Python code to evade detection.

T1059.006
Python

During ShadowRay, threat actors used the Python `pty` module to open reverse shells.

T1068
Exploitation for Privilege Escalation

During ShadowRay, threat actors downloaded a privilege escalation payload to gain root access.

T1105
Ingress Tool Transfer

During ShadowRay, threat actors downloaded and executed the XMRig miner on targeted hosts.

T1190
Exploit Public-Facing Application

During ShadowRay, threat actors exploited CVE-2023-48022 on publicly exposed Ray servers to steal computing power and to expose sensitive data.

T1496.001
Compute Hijacking

During ShadowRay, threat actors leveraged graphics processing units (GPU) on compromised nodes for cryptocurrency mining.

T1546.004
Unix Shell Configuration Modification

During ShadowRay, threat actors executed commands on interactive and reverse shells.

T1588.002
Tool

During ShadowRay, threat actors used tools including the XMRig miner and Interactsh.

Attributed groups0

MITRE does not attribute this campaign to a group.

Software0

None recorded.

References1

  1. Oligo ShadowRay Campaign MAR 2024 Open source
    Lumelsly, A. et al. (2024, March 26). ShadowRay: First Known Attack Campaign Targeting AI Workloads Actively Exploited In The Wild. Retrieved December 2, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.