Attackers Capitalize on Vulnerabilities in AhsayCBS to Deploy Cryptocurrency Miners
Recent investigations by cybersecurity researchers at Huntress have uncovered alarming activities involving two newly disclosed vulnerabilities in AhsayCBS, the management console for Ahsay’s cloud backup software. These vulnerabilities are being exploited to gain unauthorized access to servers, allowing attackers to covertly run cryptocurrency miners.
AhsayCBS, or Cloud Backup Server, serves a crucial role for managed service providers (MSPs) and system integrators. It enables these organizations to create user accounts and manage backup policies for their clientele. By October 8, Huntress had identified that at least five organizations fell victim to targeted attacks leveraging these vulnerabilities.
Rapid Exploitation Following Vulnerability Disclosure
The vulnerabilities in question are identified as CVE-2026-105133 and CVE-2026-105134. These issues were officially published in the US National Vulnerability Database (NVD) on October 4. However, by October 7 at 23:20 UTC, Huntress observed exploitation attempts, showcasing the rapid pace at which these vulnerabilities could be weaponized.
CVE-2026-105133 is described as a medium-severity vulnerability located within the checkSysPwd function, which can lead to poor authentication practices. In contrast, CVE-2026-105134 is categorized as critical, impacting the /rps/api/json/UpdateReceivers.do endpoint in the Replication Receiver component. The critical flaw allows an unauthenticated remote code execution as NT AUTHORITY\SYSTEM, evading traditional security measures by permitting a random token to serve as a proxy for legitimate credentials.
Attackers effectively combined these two vulnerabilities, bypassing initial authentication barriers before unleashing code execution capabilities. Consequently, they were able to configure a malicious replication receiver and deploy a JSP web shell within the application directory managed by CBS. Huntress first detected this malicious activity through suspicious command-line outputs generated by the cbssvcX64.exe service.
It’s important to note that versions of AhsayCBS up to 10.3.2 are affected, while version 10.3.4, released on August 5, remains secure against these particular vulnerabilities.
Concealed Cryptocurrency Mining Operation
After breaching the system, attackers proceeded to download various payloads from an Alibaba Cloud object storage host. Among these payloads was an XMRig Monero miner disguised as the legitimate Microsoft Edge application (labelled as edge.exe), along with a modified version of the NSSM service utility (renamed msedge.exe). The criminals cleverly configured the miner to operate as a SYSTEM-level service named MicrosoftEdgeUpdateSvc, camouflaging it as a genuine Edge update service while establishing a connection to a Monero mining pool on port 8029.
To evade detection, the attackers leveraged a PowerShell script known as Taskgmr.ps1. This script was designed to stop the fake Edge service whenever Task Manager was opened, thereby obscuring the mining operations from system administrators. Moreover, the script implemented measures to kill the Task Manager application itself if it was left open for over an hour overnight, relying on the local clock of the compromised endpoint rather than UTC timing. Notably, Huntress has remarked that the script exhibits signs of being AI-assisted, evidenced by its thoughtfully commented code.
In another instance of exploitation, the attackers introduced a legitimate yet vulnerable kernel driver, WinRing0x64.sys, into the compromised system. Such a tactic is common among cybercriminals, as it can disable endpoint security tools. By employing this driver, attackers were provided with kernel-level access, further reinforcing their control over the hardware.
Recommendations for Organizations
In light of these urgent security threats, Huntress is actively advising organizations utilizing AhsayCBS to take immediate action:
- Upgrade to version 10.3.4 without delay.
- Restrict access to the AhsayCBS management web interface to trusted IP addresses only, or implement VPN access for additional security measures.
- Re-image any compromised hosts from a trusted backup source, as attackers may have installed further backdoors.
- Implement Sigma detection rules and block the indicators of compromise published by Huntress, which include mining pool addresses, payload URLs, and specific file hashes.
Huntress has stated it is collaborating with potentially affected organizations to ensure these essential mitigations are applied swiftly and effectively. As cybersecurity threats continue to evolve, vigilance, and prompt action become indispensable tools in safeguarding sensitive information and maintaining operational integrity.
Further details, including comprehensive research on indicators of compromise and detection protocols, can be accessed at Huntress’s official blog. It is crucial for organizations to prioritize their cybersecurity measures to prevent falling victim to similar exploitations in the future.

