Cybersecurity experts have identified a concerning trend in which attackers are exploiting vulnerabilities in the AhsayCBS backup utility to gain control of systems and deploy cryptocurrency miners. These flaws, recently disclosed, have allowed threat actors to install web shells and XMRig miners that are cleverly disguised as Microsoft Edge.
Details of Vulnerabilities
The identified vulnerabilities, CVE-2026-105133 and CVE-2026-105134, carry CVSS scores of 5.5 and 9.3, respectively. The first involves improper authentication in the checkSysPwd() function, while the second allows for operating system command injection in the Replication Receiver component. Together, these flaws enable remote attackers to bypass authentication protocols and execute arbitrary commands.
Discovered on October 4, 2026, these vulnerabilities have been targeted since October 7, 2026, with attackers leveraging them to achieve remote code execution. As of October 8, 2026, five organizations are known to have been impacted.
Attack Methodology and Tools
Following successful exploitation, attackers conduct system reconnaissance, plant web shells, and deploy XMRig miners disguised as ‘edge.exe’ to avoid detection. A PowerShell script, ‘Taskgmr.ps1’, is utilized to facilitate these operations. This script, possibly created with AI assistance, includes anti-analysis features that halt mining if the Windows Task Manager is detected open, and it automatically closes the Task Manager after prolonged overnight activity.
Although recent advisories claim that these issues are resolved in AhsayCBS version 10.3.4, Huntress reports the vulnerabilities persist, effectively categorizing them as zero-days. In some cases, attackers have used ‘certutil.exe’ to download a vulnerable driver, aiming for kernel-level access to enhance mining efficiency.
Recommendations for Mitigation
In the absence of a comprehensive patch, limiting access to the AhsayCBS management interface is crucial. It’s recommended that organizations restrict web access to trusted IPs or implement VPN requirements. This strategy aims to prevent exploitation of the web app service, which is externally accessible on the host.
As organizations work to mitigate these threats, maintaining vigilance for signs of compromise and monitoring system activity is essential. Proactive measures will be critical in preventing unauthorized access and securing systems against future attacks.
