ATT&CKReferencesOligo ShadowRay Campaign MAR 2024

Oligo ShadowRay Campaign MAR 2024

Lumelsly, A. et al. (2024, March 26). ShadowRay: First Known Attack Campaign Targeting AI Workloads Actively Exploited In The Wild. Retrieved December 2, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns1

Procedure examples10

TechniqueUsed byProcedure example
T1003.008
/etc/passwd and /etc/shadow
CampaignShadowRay

During ShadowRay, threat actors used `cat /etc/shadow` to steal password hashes.

T1016
System Network Configuration Discovery
CampaignShadowRay

During ShadowRay, threat actors invoked DNS queries from targeted machines to identify their IP addresses.

T1027.013
Encrypted/Encoded File
CampaignShadowRay

During ShadowRay, threat actors used Base64-encrypted Python code to evade detection.

T1059.006
Python
CampaignShadowRay

During ShadowRay, threat actors used the Python `pty` module to open reverse shells.

T1068
Exploitation for Privilege Escalation
CampaignShadowRay

During ShadowRay, threat actors downloaded a privilege escalation payload to gain root access.

T1105
Ingress Tool Transfer
CampaignShadowRay

During ShadowRay, threat actors downloaded and executed the XMRig miner on targeted hosts.

T1190
Exploit Public-Facing Application
CampaignShadowRay

During ShadowRay, threat actors exploited CVE-2023-48022 on publicly exposed Ray servers to steal computing power and to expose sensitive data.

T1496.001
Compute Hijacking
CampaignShadowRay

During ShadowRay, threat actors leveraged graphics processing units (GPU) on compromised nodes for cryptocurrency mining.

T1546.004
Unix Shell Configuration Modification
CampaignShadowRay

During ShadowRay, threat actors executed commands on interactive and reverse shells.

T1588.002
Tool
CampaignShadowRay

During ShadowRay, threat actors used tools including the XMRig miner and Interactsh.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.