HomeCyber BalkansAttackers Exploit AhsayCBS Backup Vulnerabilities to Deploy Disguised Crypto Miners

Attackers Exploit AhsayCBS Backup Vulnerabilities to Deploy Disguised Crypto Miners

Published on

spot_img

Attackers Capitalize on Vulnerabilities in AhsayCBS to Deploy Cryptocurrency Miners

Recent investigations by cybersecurity researchers at Huntress have uncovered alarming activities involving two newly disclosed vulnerabilities in AhsayCBS, the management console for Ahsay’s cloud backup software. These vulnerabilities are being exploited to gain unauthorized access to servers, allowing attackers to covertly run cryptocurrency miners.

AhsayCBS, or Cloud Backup Server, serves a crucial role for managed service providers (MSPs) and system integrators. It enables these organizations to create user accounts and manage backup policies for their clientele. By October 8, Huntress had identified that at least five organizations fell victim to targeted attacks leveraging these vulnerabilities.

Rapid Exploitation Following Vulnerability Disclosure

The vulnerabilities in question are identified as CVE-2026-105133 and CVE-2026-105134. These issues were officially published in the US National Vulnerability Database (NVD) on October 4. However, by October 7 at 23:20 UTC, Huntress observed exploitation attempts, showcasing the rapid pace at which these vulnerabilities could be weaponized.

CVE-2026-105133 is described as a medium-severity vulnerability located within the checkSysPwd function, which can lead to poor authentication practices. In contrast, CVE-2026-105134 is categorized as critical, impacting the /rps/api/json/UpdateReceivers.do endpoint in the Replication Receiver component. The critical flaw allows an unauthenticated remote code execution as NT AUTHORITY\SYSTEM, evading traditional security measures by permitting a random token to serve as a proxy for legitimate credentials.

Attackers effectively combined these two vulnerabilities, bypassing initial authentication barriers before unleashing code execution capabilities. Consequently, they were able to configure a malicious replication receiver and deploy a JSP web shell within the application directory managed by CBS. Huntress first detected this malicious activity through suspicious command-line outputs generated by the cbssvcX64.exe service.

It’s important to note that versions of AhsayCBS up to 10.3.2 are affected, while version 10.3.4, released on August 5, remains secure against these particular vulnerabilities.

Concealed Cryptocurrency Mining Operation

After breaching the system, attackers proceeded to download various payloads from an Alibaba Cloud object storage host. Among these payloads was an XMRig Monero miner disguised as the legitimate Microsoft Edge application (labelled as edge.exe), along with a modified version of the NSSM service utility (renamed msedge.exe). The criminals cleverly configured the miner to operate as a SYSTEM-level service named MicrosoftEdgeUpdateSvc, camouflaging it as a genuine Edge update service while establishing a connection to a Monero mining pool on port 8029.

To evade detection, the attackers leveraged a PowerShell script known as Taskgmr.ps1. This script was designed to stop the fake Edge service whenever Task Manager was opened, thereby obscuring the mining operations from system administrators. Moreover, the script implemented measures to kill the Task Manager application itself if it was left open for over an hour overnight, relying on the local clock of the compromised endpoint rather than UTC timing. Notably, Huntress has remarked that the script exhibits signs of being AI-assisted, evidenced by its thoughtfully commented code.

In another instance of exploitation, the attackers introduced a legitimate yet vulnerable kernel driver, WinRing0x64.sys, into the compromised system. Such a tactic is common among cybercriminals, as it can disable endpoint security tools. By employing this driver, attackers were provided with kernel-level access, further reinforcing their control over the hardware.

Recommendations for Organizations

In light of these urgent security threats, Huntress is actively advising organizations utilizing AhsayCBS to take immediate action:

  1. Upgrade to version 10.3.4 without delay.
  2. Restrict access to the AhsayCBS management web interface to trusted IP addresses only, or implement VPN access for additional security measures.
  3. Re-image any compromised hosts from a trusted backup source, as attackers may have installed further backdoors.
  4. Implement Sigma detection rules and block the indicators of compromise published by Huntress, which include mining pool addresses, payload URLs, and specific file hashes.

Huntress has stated it is collaborating with potentially affected organizations to ensure these essential mitigations are applied swiftly and effectively. As cybersecurity threats continue to evolve, vigilance, and prompt action become indispensable tools in safeguarding sensitive information and maintaining operational integrity.

Further details, including comprehensive research on indicators of compromise and detection protocols, can be accessed at Huntress’s official blog. It is crucial for organizations to prioritize their cybersecurity measures to prevent falling victim to similar exploitations in the future.

Source link

Latest articles

This Week’s Essential Patch for NetScaler ADC and NetScaler Gateway Is Available

Citrix Faces Security Challenges: Urgent Recommendations for Users In recent developments, Citrix has found itself...

Your Phishing Drill Numbers Are Misleading You

Why Measuring What Employees Do Matters More Than Tracking What They Complete In the realm...

Q3 2026 Breaks Record for Ransomware Attacks

Ransomware attacks surged to unprecedented levels in the third quarter of 2026, reaching the...

Live Webinar – Modernizing Enterprise Data Security for the AI Era: Essential Changes and Initial Steps

Navigating Data Security in the Age of AI: Key Insights from Proofpoint's Webinar In an...

More like this

This Week’s Essential Patch for NetScaler ADC and NetScaler Gateway Is Available

Citrix Faces Security Challenges: Urgent Recommendations for Users In recent developments, Citrix has found itself...

Your Phishing Drill Numbers Are Misleading You

Why Measuring What Employees Do Matters More Than Tracking What They Complete In the realm...

Q3 2026 Breaks Record for Ransomware Attacks

Ransomware attacks surged to unprecedented levels in the third quarter of 2026, reaching the...