Attackers Exploit AhsayCBS Vulnerabilities to Deploy Web Shell and Cryptocurrency Miner
Attackers are exploiting two vulnerabilities in the AhsayCBS backup management platform to deploy a Java Server Page (JSP) web shell and an XMRig cryptocurrency miner.
AhsayCBS is commonly used by managed service providers (MSPs) and system integrators. Huntress observed the malicious activity on October 7 and reported that at least five organizations were targeted.
AhsayCBS vulnerabilities exploited in attacks
The two security issues involved in the attacks are:
- CVE-2026-105133, an authentication bypass vulnerability with a public exploit.
- CVE-2026-105134, which can be used for operating system command injection.
Both vulnerabilities were reportedly fixed in AhsayCBS 10.3.2. However, researchers at managed detection and response company Huntress discovered that the flaws also affect the current latest version, Ahsay 10.3.4.
“After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities,” Huntress said in an update.
Attackers chain flaws to install web shell and XMRig miner
In the observed attack, the threat actor chained the two vulnerabilities together, first bypassing authentication with CVE-2026-105133 and then executing commands using CVE-2026-105134.
After gaining access, Huntress observed the attacker conducting reconnaissance, deploying a JSP web shell, and downloading an XMRig cryptocurrency miner disguised as edge.exe.
The miner persists on the compromised host through a service named MicrosoftEdgeUpdateSvc and executes as msedge.exe. Huntress identified the service as a modified copy of the legitimate Non-Sucking Service Manager (NSSM) utility.
The attacker also deployed a PowerShell file named Taskgmr.ps1. Huntress believes the script was created with the assistance of AI. It attempts to hide the mining activity by stopping the service when Task Manager opens and restarting the service when Task Manager closes.
The script also closes if Task Manager is closed at 6 p.m. local time or if Task Manager remains open for more than an hour at night.
In one incident, the attacker deployed the vulnerable WinRing0x64.sys driver, likely in an attempt to unlock additional hardware resources for cryptocurrency mining.
AhsayCBS customers urged to restrict management access
BleepingComputer contacted AhsayCBS to ask about plans to fix the two flaws but had not received a response at the time of publication.
Until a patch is available, Huntress recommends that system administrators restrict access to the AhsayCBS management interface to trusted IP addresses only and investigate their systems for signs of compromise.
If a compromise is confirmed, administrators should fully restore the affected host from a secure backup because the attacker may have installed additional backdoors for long-term persistence.
Huntress has also provided an indicator of compromise (IoC) for this activity and four Sigma rules to help defenders detect it.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



