CARDS
CARDS
ShadowRay was a campaign that began in late 2023 targeting the education, cryptocurrency, biopharma, and other sectors through a vulnerability (CVE-2023-48022) in the Ray AI framework named ShadowRay. According to security researchers ShadowRay was the first known instance of AI workloads being activley exploited in the wild through vulnerabilities in AI infrastructure. CVE-2023-48022, which allows access to compute resources and sensitive data for exposed instances, remains unpatched and has been disputed by the vendor as they maintain that Ray is not intended for use outside of a strictly controlled network environment.
Last updated Aug 24, 2026, 6:00 AM EDT
Evidence Boundary
Bottom Line Up Front
ShadowRay was a campaign that began in late 2023 targeting the education, cryptocurrency, biopharma, and other sectors through a vulnerability (CVE-2023-48022) in the Ray AI framework named ShadowRay. According to security researchers ShadowRay was the first known instance of AI workloads being activley exploited in the wild through vulnerabilities in AI infrastructure. CVE-2023-48022, which allows access to compute resources and sensitive data for exposed instances, remains unpatched and has been disputed by the vendor as they maintain that Ray is not intended for use outside of a strictly controlled network environment.[1][2][3]
Potential espionage, credential theft, operational disruption, or data exposure depending on campaign objective.[1][2][3]
Map local telemetry to the listed ATT&CK techniques before assuming exposure. Review identity, endpoint, network egress, and cloud audit evidence for campaign-specific behavior. Keep attribution and victimology source-bound unless corroborated by local evidence.[1][2][3]
Decision Summary
ShadowRay was a campaign that began in late 2023 targeting the education, cryptocurrency, biopharma, and other sectors through a vulnerability (CVE-2023-48022) in the Ray AI framework named ShadowRay. According to security researchers ShadowRay was the first known instance of AI workloads being activley exploited in the wild through vulnerabilities in AI infrastructure. CVE-2023-48022, which allows access to compute resources and sensitive data for exposed instances, remains unpatched and has been disputed by the vendor as they maintain that Ray is not intended for use outside of a strictly controlled network environment.
The retained record scopes this as threat actor campaign activity during 2023-09-01 to 2024-03-01. Potential espionage, credential theft, operational disruption, or data exposure depending on campaign objective.[1][2][3]
Map local telemetry to the listed ATT&CK techniques before assuming exposure. Review identity, endpoint, network egress, and cloud audit evidence for campaign-specific behavior. Keep attribution and victimology source-bound unless corroborated by local evidence.[1][2][3]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for MITRE-tracked campaign metadata and ATT&CK relationships; operational currentness should be validated..[1][2][3]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
Campaign row is compressed for directory seeding. Confirm actor linkage, infrastructure, and targeting with source-specific reports and local telemetry.
IntelliOS
None Found
Citations