Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors IronErn440

Also known as: PCPcat, ShellForce, CipherForce, DeadCatx3, CanisterWorm, tracked as, YoroTrooper, Russia, China, UNC4057, Star Blizzard, a Russian state-sponsored group, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, allows remote, CVE-2023-48022, Cavalry Werewolf, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Monsoon, Sarit, Dropping Elephant, APT-C-09, ZINC EMERSON, ATK11, G0040, Orange Athos, Thirsty Gemini

Description

IronErn440 emerges as a multi‑faceted adversary that orchestrates attacks against high‑value targets by combining traditional spear‑phishing with advanced cloud exploitation. In September 2023 the group publicly demonstrated its capabilities against Ray AI clusters, exploiting CVE‑2023‑48022 to gain unauthenticated remote code execution in more than 200,000 exposed instances. Once inside a cluster, IronErn440 deploys self‑propagating payloads that leverage Kubernetes NodeAffinitySchedulingStrategy to spread laterally across worker nodes. The payload establishes persistent backdoors via cron and systemd timers, injects multi‑port Python reverse shells, and installs OpenSSH servers with obfs4 Tor bridges for covert command & control. A hallmark of the actor is its use of GPU‑optimized miners—XMRig and Rigel GPU Miner—that masquerade as legitimate processes such as dns-filter or kworker/0:0. Concurrently, the malware wipes competing miners, throttles CPU usage to 60 %, and updates via a cron job every 15 minutes. Beyond cryptojacking, IronErn440 executes data theft and exfiltration through custom LZSS‑compressed ELF droppers and leverages social engineering—malicious Word documents exploiting the EPS dictionary copy use‑after‑free (CVE‑2015‑1701)—to drop IRONHALO or ELMER backdoors. The actor also engages in distributed denial‑of‑service with tools like sockstress, MINIBIKE, and TWOSTROKE, often orchestrated through its ShadowRay 2.0 command & control network.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Aerospace
Energy
Telecommunications
Education
Media
Information technology
Think tank
Mining
Healthcare
Manufacturing
Maritime
Pharmaceutical
Critical infrastructure
Aviation
Chemical
Transportation
Oil gas
Utilities
Food agriculture
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
CN
GB
IN
IR
JP
DE
RU
KR
SA
FR
CA
TW
IL
AU
KZ
TR
UA
PK
AE
VN
PL
BY
KP
AZ
SG
NL
BR
ES
IQ
IT
SY
MX
RO
EG

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

IronErn440 is a sophisticated threat actor that blends spear‑phishing, exploitation of the Ray AI framework vulnerability CVE‑2023‑48022, and automated GitLab/CI‑CD pipelines to deploy large‑scale cryptojacking, data exfiltration, and DDoS campaigns. Their operations target government, defense, finance, aerospace, and critical infrastructure sectors across dozens of nations, using custom stagers and popular RATs such as Poison Ivy. Defenders should harden Ray clusters, block malicious attachment delivery, and monitor for cryptomining signatures to mitigate risk.

Goals & Targeting

IronErn440’s strategic objectives appear to be multi‑layered: first, establish a resilient botnet that can harvest cryptocurrency revenue; second, exfiltrate sensitive data from high‑profile sectors for espionage or political leverage; third, conduct opportunistic DDoS campaigns against competitors or adversarial entities. The actor shows a preference for cloud and AI‑infrastructure assets—particularly Ray clusters—allowing rapid expansion while remaining low‑footprint within target environments. Their victim profile spans government, defense, finance, aerospace, and critical infrastructure, with a global reach that includes the US, China, Europe, Latin America, and the Middle East. IronErn440’s operations emphasize stealth (cryptocurrency mining masqueraded as system processes) and speed (rapid lateral spread via Kubernetes policies), enabling repeated compromise cycles across geographically diverse networks. The combination of credential theft, cryptojacking profits, and politically salient data extraction points to a resource‑rich adversary with both state sponsorship connotations and commercial exploitation motives.

Enhanced Description

Key Capabilities

  • Spear‑phishing via ZIP attachments containing LNK shortcuts
  • PowerShell stagers installing OpenSSH servers and obfs4 Tor bridges
  • Scheduled task persistence using cron or systemd timers
  • Exploitation of CVE‑2023‑48022 on Ray AI clusters for unauthenticated RCE
  • Self‑propagating deployment with NodeAffinitySchedulingStrategy
  • Multi‑port Python reverse shells
  • GPU‑tuned cryptominers masquerading as legitimate processes like dns‑filter or kworker/0:0
  • Manipulation of iptables and /etc/hosts entries to hide activity
  • Use of GitLab/GitHub CI/CD pipelines for automated payload distribution
  • Cryptojacking via XMRig or Rigel GPU miner
  • Data theft and exfiltration through custom ELF dropper binaries
  • Rapid propagation across compromised nodes with CRASHPAD and SIGHTGRAB utilities
  • Distributed denial‑of‑service attacks using sockstress, MINIBIKE and TWOSTROKE

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Exfiltration
Command & Control

ATT&CK Techniques

T1566.001
T1204.002
T1059.003
T1105
T1053
T1190
T1036
T1552.001

Software / Tooling

9002 RAT
Poison Ivy
NOROBOT
YESROBOT
MAYBEROBOT
ShadowRay 2.0
XMRig
Rigel GPU miner
sockstress
MINIBIKE
TWOSTROKE
DEEPROOT
GHOSTLINE
LIGHTRAIL
POLLBLEND
CRASHPAD
SIGHTGRAB
TRUSTTRAP
DCSYNCER.SLICK
IRONHALO
ELMER
MiniDuke
CosmicDuke
OnionDuke
CozyDuke
CloudDuke
SeaDuke
HammerDuke
PinchDuke
GeminiDuke
MiniDionis
Hammertoss
Chinastrats
Patchwork
Dropping Elephant

Campaigns & Victims

Since the public disclosure of CVE‑2023‑48022, IronErn440 has mounted a systematic campaign dubbed ShadowRay 2.0 that turns exposed Ray AI clusters into botnet nodes. The attack chain begins with spear‑phishing and continues through exploitation of the RCE flaw, yielding immediate footholds which are then expanded by self‑propagating payloads. The group frequently leverages Kubernetes scheduling policies to infect hundreds or thousands of worker pods in a single day. Operational tempo is high; many clusters receive updates via a cron job every fifteen minutes, enabling rapid rollback and evasion of forensic analysis. Victims have spanned government agencies, defense contractors, financial firms, aerospace manufacturers, and critical infrastructure providers across at least twenty‑seven countries. Notable historical operations include a 2015 spear‑phishing wave that deployed IRONHALO backdoors and leveraged the EPS dictionary copy vulnerability; more recent campaigns have introduced cryptojacking as a primary revenue generator while also conducting DDoS sweeps against mining pools using tools such as sockstress. In addition to RCE, IronErn440 has been observed using public RATs like Poison Ivy and custom ELF loaders, indicating a tendency to mix commodity malware with bespoke code to broaden attack surfaces and circumvent detection.

IOC Patterns

  • Exposed Ray AI clusters vulnerable to CVE‑2023‑48022
  • Spear‑phishing ZIP attachments containing LNK shortcuts
  • PowerShell stagers installing OpenSSH servers and obfs4 Tor bridges
  • Scheduled task persistence via cron/systemd
  • GPU‑tuned cryptominers masquerading as dns‑filter or kworker/0:0 processes
  • Manipulation of iptables and /etc/hosts entries to hide malicious activity
  • Use of GitLab/GitHub CI/CD pipelines for payload distribution
  • Custom compressed ELF binaries utilizing LZSS
  • Exploitation of EPS dictionary copy use‑after‑free vulnerability (CVE‑2015‑1701)
  • Presence of cryptomining binaries such as XMRig and Rigel GPU miner
  • Indicators of botnet propagation scripts and DDoS tools

Recommended Actions

  • Implement email filtering and attachment scanning that detects LNK shortcuts within ZIP files.
  • Patch or harden Ray AI clusters against CVE‑2023‑48022, or disable unauthenticated remote execution mechanisms.
  • Block unauthorized installation of OpenSSH servers and obfs4 Tor bridges on corporate networks.
  • Audit scheduled tasks (cron/systemd) regularly to spot unknown persistence scripts.
  • Deploy host‑based intrusion detection rules that flag cryptomining binaries masquerading as legitimate processes like dns-filter or kworker/0:0.
  • Monitor and log changes to iptables and /etc/hosts filesystem entries for anomalous modifications.
  • Isolate CI/CD pipeline environments from production infrastructure and enforce least‑privilege access. Conduct phishing awareness training focusing on malicious Word attachments that exploit CVE‑2015‑1701 and the EPS dictionary copy vulnerability. Apply Office patches promptly to mitigate known vulnerabilities. Detect and block known cryptomining binaries (XMRig, Rigel GPU miner) through file‑hash or behavioral monitoring. Review cloud infrastructure logs for anomalous botnet activity, rapid propagation patterns, and DDoS signatures.

Suggested Tags

Russian state-sponsored
APT28
Spear-phishing
Phishing attachment
CVE-2023-48022
Ray AI exploitation
Cryptomining
OpenSSH installation
Obfs4 Tor bridge
GitLab CI/CD
cryptojacking
botnet
spearphishing-attachment
CVE2015-1701
EPS-dictionary-exploit
PoisonIvy
shadowray
cloud-based-botnets
cryptocurrency-mining
sockstress
XMRig
Rigel-GPU-miner
AI/ML-infrastructure-target
defense-technology-sector
financial-sector
China-actor

Confidence Assessment

The attribution to IronErn440 draws on multiple intelligence feeds describing consistent TTPs, tool usage, and target profiles. Confidence is moderate‑high given repeated corroboration across public sources but constrained by gaps in precise operational timelines and definitive state sponsorship evidence. Unresolved information includes exact first/last seen dates, full scope of affected sectors beyond listed samples, and definitive financial impact metrics from cryptojacking operations.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.securonix.com — Cited by web research for: YoroTrooper
  2. misp-galaxy.org — Cited by web research for: cpyy
  3. www.securityweek.com — Cited by web research for: allows remote
  4. threats.wiz.io — Cited by web research for: CVE-2023-48022
  5. cyberpress.org — Cited by web research for: WhatsApp
  6. https://gitlab.com/ironern440-group/ironern440-project/-/raw/main/run-CN — Cited by AI analysis.

Intel Summary

8

Techniques

76

Tools

0

Campaigns

39

IOCs

0

Observed Data

5

Tactics

Tags

Critical Infrastructure
Backdoor / C2
DDoS
APT
Malware
Crypto-Mining
AI Infrastructure Targeting
Russian state-sponsored
APT28
Spear-phishing
Phishing attachment
CVE-2023-48022
Ray AI exploitation
Cryptomining
OpenSSH installation
Obfs4 Tor bridge
GitLab CI/CD
cryptojacking
botnet
spearphishing-attachment
CVE2015-1701
EPS-dictionary-exploit
PoisonIvy
shadowray
cloud-based-botnets
cryptocurrency-mining
sockstress
XMRig
Rigel-GPU-miner
AI/ML-infrastructure-target
defense-technology-sector
financial-sector
China-actor

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.