
Huntress Sees Active Exploitation of AhsayCBS Backup Flaws Dropping Webshells and XMRig Across Five Organizations
Huntress says attackers began chaining two AhsayCBS flaws on Oct. 7 to gain SYSTEM-level remote code execution, then planted JSP webshells, an XMRig miner disguised as Microsoft Edge, and an AI-assisted PowerShell script that hides mining when Task Manager is open. Four Sigma rules and IOCs are published for defenders.
Noah Park, ResponseNew York6 min read
NEW YORK - Within three days of public disclosure, attackers were already chaining two flaws in AhsayCBS, a backup management console widely used by managed service providers, to run code as NT AUTHORITY/SYSTEM on exposed hosts. In a report published on Oct. 8, Huntress said it first saw the activity at 23:20:15 UTC on Oct. 7 and, by the next day, had counted five customer organizations hit. Post-exploitation, the actors dropped Java Server Page webshells, planted an XMRig cryptominer renamed to look like Microsoft Edge, and ran what Huntress described as an AI-assisted PowerShell script that watches Task Manager and shuts mining down when an operator is looking.
The flaws were listed by NVD on Oct. 4. CVE-2026-105133 is a medium-severity improper authentication issue in the checkSysPwd function of AhsayCBS. CVE-2026-105134 is a critical unauthenticated remote code execution path through the Replication Receiver endpoint at /rps/api/json/UpdateReceivers.do, where a random token can stand in for valid credentials. Huntress said the two are chained: the first bypasses authentication, then the second yields code execution. After exploitation, operators configured a malicious receiver and dropped a JSP webshell into the application directory the CBS console serves. Versions through 10.3.4 are affected. An Oct. 8 evening update corrected earlier guidance that had carved 10.3.4 out; Huntress said it has contacted Ahsay with its findings and, until a patch ships, recommends restricting management-interface access to trusted networks or a VPN.
The first Huntress signals were suspicious child processes spawning from the AhsayCBS service binaries cbssvcX64.exe and cbssvcX86.exe. Across several incidents, that service pulled Taskgmr.ps1, msedge.exe, edge.exe and config.json from an Alibaba Cloud Object Storage host at imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com into Temp folders. The edge.exe binary is XMRig. It connected to an XMR pool on port 8029 at xmr.kryptex[.]network and 51.195.127[.]124. Actors used PowerShell to edit config.json, then created a Windows service named MicrosoftEdgeUpdateSvc, designed to resemble the legitimate Edge update service, that ran msedge.exe from Temp as SYSTEM. Huntress said msedge.exe is a modified copy of the NSSM utility, used here to keep the miner alive across crashes and reboots. VirusTotal labels for that hash clustered around NSSM hacktool detections.


Taskgmr.ps1 is the piece Huntress called out as likely AI-assisted, citing its commented structure. The script continuously checks for Task Manager. If Task Manager is open, it stops MicrosoftEdgeUpdateSvc to hide the miner; when Task Manager closes, it restarts the service. It also kills Task Manager at 18:00 local time and if Task Manager stays open for more than an hour overnight, using the host's local Get-Date clock rather than UTC. In one incident, certutil.exe fetched WinRing0x64.sys, a known vulnerable kernel driver from the WinRing0 library, into Temp. Huntress assessed the driver was loaded to give the miner kernel-level hardware access rather than to disable endpoint tools, a pattern previously reported in unrelated mining campaigns.

For defenders, Huntress published four Sigma rules in its threat-intel repository under 2026/2026-10/AhsayCBS_XMRig_Miner: unexpected child processes from the AhsayCBS service; Edge-named binaries launched with a daemonized flag or carrying an msedge_exe original name; PowerShell that pairs Task Manager discovery with service start or stop; and command lines that download WinRing0 alongside a URL. Recommended mitigations are to lock down the management web interface immediately, hunt the published IOCs, and fully re-image any compromised host from trusted backup because secondary backdoors may remain. Huntress sells endpoint detection and response used by the organizations in these incidents. Network infrastructure IOCs span Hong Kong, Vietnam, France, Taiwan and United States ASNs; payload SHA-256 hashes for msedge.exe, edge.exe and Taskgmr.ps1 are listed at the end of the Huntress post.
Sources:
Noah Park covers incident response and blue-team operations for SOCtember from New York.
Related stories
Response
FBI and Secret Service Warn FortiBleed Hackers Are Locking Some Fortinet Customers Out of Their Own Firewalls
Detection
Attackers Are Testing Stolen AWS Keys for Amazon Bedrock Access, Leaving a Pattern Defenders Can Spot
Detection
Malware Now Embeds Instructions Meant to Steer AI Analysis Tools, Cisco Talos Finds Across 84 Samples
Response