Beam clusters hijacked and turned into crypto miners by shadowy new botnet


  • Ray clusters remain vulnerable to remote code execution via unauthorized Jobs API
  • Threat group “IronErn440” exploits flaws with AI-generated payloads by deploying XMRig cryptojacker
  • Over 230,000 Ray servers are exposed online, up from a few thousand in 2023

Beam clusters still vulnerable to a critical severity flaw discovered years ago are being used for cryptocurrency mining, data exfiltration and even Distributed Denial of Service (DDoS) attacks, experts have warned.

Cybersecurity researchers Oligo claim this is the second major campaign to exploit the same flaw.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top