Also known as: PCPcat, ShellForce, CipherForce, DeadCatx3, CanisterWorm, tracked as, YoroTrooper, Russia, China, UNC4057, Star Blizzard, a Russian state-sponsored group, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, allows remote, CVE-2023-48022, Cavalry Werewolf, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork, iKittens, Group 83, NewsBeef, G0058, CharmingCypress, Mint Sandstorm, Monsoon, Sarit, Dropping Elephant, APT-C-09, ZINC EMERSON, ATK11, G0040, Orange Athos, Thirsty Gemini
IronErn440 emerges as a multi‑faceted adversary that orchestrates attacks against high‑value targets by combining traditional spear‑phishing with advanced cloud exploitation. In September 2023 the group publicly demonstrated its capabilities against Ray AI clusters, exploiting CVE‑2023‑48022 to gain unauthenticated remote code execution in more than 200,000 exposed instances. Once inside a cluster, IronErn440 deploys self‑propagating payloads that leverage Kubernetes NodeAffinitySchedulingStrategy to spread laterally across worker nodes. The payload establishes persistent backdoors via cron and systemd timers, injects multi‑port Python reverse shells, and installs OpenSSH servers with obfs4 Tor bridges for covert command & control. A hallmark of the actor is its use of GPU‑optimized miners—XMRig and Rigel GPU Miner—that masquerade as legitimate processes such as dns-filter or kworker/0:0. Concurrently, the malware wipes competing miners, throttles CPU usage to 60 %, and updates via a cron job every 15 minutes. Beyond cryptojacking, IronErn440 executes data theft and exfiltration through custom LZSS‑compressed ELF droppers and leverages social engineering—malicious Word documents exploiting the EPS dictionary copy use‑after‑free (CVE‑2015‑1701)—to drop IRONHALO or ELMER backdoors. The actor also engages in distributed denial‑of‑service with tools like sockstress, MINIBIKE, and TWOSTROKE, often orchestrated through its ShadowRay 2.0 command & control network.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
IronErn440 is a sophisticated threat actor that blends spear‑phishing, exploitation of the Ray AI framework vulnerability CVE‑2023‑48022, and automated GitLab/CI‑CD pipelines to deploy large‑scale cryptojacking, data exfiltration, and DDoS campaigns. Their operations target government, defense, finance, aerospace, and critical infrastructure sectors across dozens of nations, using custom stagers and popular RATs such as Poison Ivy. Defenders should harden Ray clusters, block malicious attachment delivery, and monitor for cryptomining signatures to mitigate risk.
Goals & Targeting
IronErn440’s strategic objectives appear to be multi‑layered: first, establish a resilient botnet that can harvest cryptocurrency revenue; second, exfiltrate sensitive data from high‑profile sectors for espionage or political leverage; third, conduct opportunistic DDoS campaigns against competitors or adversarial entities. The actor shows a preference for cloud and AI‑infrastructure assets—particularly Ray clusters—allowing rapid expansion while remaining low‑footprint within target environments. Their victim profile spans government, defense, finance, aerospace, and critical infrastructure, with a global reach that includes the US, China, Europe, Latin America, and the Middle East. IronErn440’s operations emphasize stealth (cryptocurrency mining masqueraded as system processes) and speed (rapid lateral spread via Kubernetes policies), enabling repeated compromise cycles across geographically diverse networks. The combination of credential theft, cryptojacking profits, and politically salient data extraction points to a resource‑rich adversary with both state sponsorship connotations and commercial exploitation motives.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Since the public disclosure of CVE‑2023‑48022, IronErn440 has mounted a systematic campaign dubbed ShadowRay 2.0 that turns exposed Ray AI clusters into botnet nodes. The attack chain begins with spear‑phishing and continues through exploitation of the RCE flaw, yielding immediate footholds which are then expanded by self‑propagating payloads. The group frequently leverages Kubernetes scheduling policies to infect hundreds or thousands of worker pods in a single day. Operational tempo is high; many clusters receive updates via a cron job every fifteen minutes, enabling rapid rollback and evasion of forensic analysis. Victims have spanned government agencies, defense contractors, financial firms, aerospace manufacturers, and critical infrastructure providers across at least twenty‑seven countries. Notable historical operations include a 2015 spear‑phishing wave that deployed IRONHALO backdoors and leveraged the EPS dictionary copy vulnerability; more recent campaigns have introduced cryptojacking as a primary revenue generator while also conducting DDoS sweeps against mining pools using tools such as sockstress. In addition to RCE, IronErn440 has been observed using public RATs like Poison Ivy and custom ELF loaders, indicating a tendency to mix commodity malware with bespoke code to broaden attack surfaces and circumvent detection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The attribution to IronErn440 draws on multiple intelligence feeds describing consistent TTPs, tool usage, and target profiles. Confidence is moderate‑high given repeated corroboration across public sources but constrained by gaps in precise operational timelines and definitive state sponsorship evidence. Unresolved information includes exact first/last seen dates, full scope of affected sectors beyond listed samples, and definitive financial impact metrics from cryptojacking operations.
No campaigns linked yet.
No observed data linked yet.
8
Techniques
76
Tools
0
Campaigns
39
IOCs
0
Observed Data
5
Tactics