Threat actors are exploiting two unpatched AhsayCBS vulnerabilities to deploy webshells and cryptocurrency miners. The attacks chain an authentication bypass with OS command injection, then use PowerShell scripts and a malicious driver to hide mining activity. Huntress recommends restricting access and investigating compromise.
| IOC Type | Value | Description | Relevant MITRE ATT&CK Techniques |
|---|---|---|---|
| Filename |
edge.exe
|
Disguised XMRig miner | T1036|T1105|T1027 |
| Filename |
msedge.exe
|
Modified copy of NSSM used as service executable | T1036|T1543.002 |
| Filename |
Taskgmr.ps1
|
PowerShell script to hide mining and disable Task Manager | T1059.001|T1562.001 |
| Filename |
WinRing0x64.sys
|
Exploits CVE-2020-14979 for privilege escalation | T1566.001 |
| Service |
MicrosoftEdgeUpdateSvc
|
Malicious service for persistence | T1543.002 |
| Code | Title |
|---|---|
| T1190 | Exploit Public-Facing Application to bypass authentication |
| T1059.001 | Command and Scripting Interpet: PowerShell - PowerShell script execution for mining and evasion |
| T1105 | Ingress Tool Transfer - Ingress Tool Transfer of XMRig miner |
| T1036 | Masquerading as legitimate files (edge.exe, msedge.exe) |
| T1505.003 | Web Shell persistence via JSP webshell |
| T1543.002 | Create or Modify System Process: Service for persistence |
| T1562.001 | Disable Tools to hide mining activity |
| T1027 | Obfuscated Files or Information - Obfuscated Files or Encoding (disguised miner) |
| T1060 | Enable or Disable System Features (installing driver) |
| T1082 | System Information Discovery during reconnaissance |
| Type | Value |
|---|---|
| Sector | Managed Service Providers and system integrators |
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. AhsayCBS is typically used by managed service providers (MSPs) and system integrators. The malicious activity was observed on October 7, and targeted at least five organizations. The two security issues exploited in attacks are tracked as CVE-2026-105133 , an authentication bypass vulnerability that has a public exploit, and CVE-2026-105134, which can be leveraged for OS command injection. Both vulnerabilities are reported as fixed in AhsayCBS 10.3.2, but researchers at managed detection and response company (MDR) Huntress found that they also affect Ahsay 10.3.4, currently the latest version. "After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities," Huntress says in an update today. In the observed attacks, the threat actor chained the two vulnerabilities, CVE-2026-105133 first to bypass authentication and then CVE-2026-105134 for code execution. After gaining access, Huntress observed the attacker perform reconnaissance, deploy Java Server Page (JSP) webshells, and download the XMRig miner disguised as
BleepingComputer has contacted AhsayCBS to ask about its plans to fix the two flaws, but we have not heard back as of publication. Until a patch is available, Huntress recommends that system administrators restrict access to the AhsayCBS management interface to trusted IP addresses only, and investigate signs of compromise. If a compromise is confirmed, administrators should perform a full restore of the host from a safe backup, because the attacker may have installed additional backdoors for prolonged persistence. Huntress has also provided indicators of compromise (IoCs) for this activity, along with four Sigma rules to help defenders detect it. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat