Lumelsly, A. et al. (2024, March 26). ShadowRay: First Known Attack Campaign Targeting AI Workloads Actively Exploited In The Wild. Retrieved December 2, 2024.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.008 /etc/passwd and /etc/shadow |
CampaignShadowRay | During ShadowRay, threat actors used `cat /etc/shadow` to steal password hashes. |
| T1016 System Network Configuration Discovery |
CampaignShadowRay | During ShadowRay, threat actors invoked DNS queries from targeted machines to identify their IP addresses. |
| T1027.013 Encrypted/Encoded File |
CampaignShadowRay | During ShadowRay, threat actors used Base64-encrypted Python code to evade detection. |
| T1059.006 Python |
CampaignShadowRay | During ShadowRay, threat actors used the Python `pty` module to open reverse shells. |
| T1068 Exploitation for Privilege Escalation |
CampaignShadowRay | During ShadowRay, threat actors downloaded a privilege escalation payload to gain root access. |
| T1105 Ingress Tool Transfer |
CampaignShadowRay | During ShadowRay, threat actors downloaded and executed the XMRig miner on targeted hosts. |
| T1190 Exploit Public-Facing Application |
CampaignShadowRay | During ShadowRay, threat actors exploited CVE-2023-48022 on publicly exposed Ray servers to steal computing power and to expose sensitive data. |
| T1496.001 Compute Hijacking |
CampaignShadowRay | During ShadowRay, threat actors leveraged graphics processing units (GPU) on compromised nodes for cryptocurrency mining. |
| T1546.004 Unix Shell Configuration Modification |
CampaignShadowRay | During ShadowRay, threat actors executed commands on interactive and reverse shells. |
| T1588.002 Tool |
CampaignShadowRay | During ShadowRay, threat actors used tools including the XMRig miner and Interactsh. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.