AhsayCBS zero-days exploited to drop web shells and XMRig
Huntress reports active exploitation of two AhsayCBS flaws, CVE-2026-105133 and CVE-2026-105134, chained for unauthenticated RCE. The latest release 10.3.4 is still affected; no patch yet.
Attackers are exploiting two flaws in the AhsayCBS backup management platform to gain unauthenticated code execution, drop JSP web shells, and deploy XMRig cryptominers, according to a Huntress report published October 8. The managed-detection firm says exploitation began 2026-10-07 23:20:15 UTC and had hit five organizations by the next day. The threat actor is unidentified.
The flaws
- CVE-2026-105133 (medium) — improper authentication in the
checkSysPwd()function. - CVE-2026-105134 (critical) — OS command injection reached via
/rps/api/json/UpdateReceivers.do, which Huntress describes as unauthenticated RCE running as SYSTEM.
The two chain: CVE-2026-105133 bypasses authentication, CVE-2026-105134 executes commands. The Hacker News, citing the NVD advisories, puts the CVSS v4 scores at 5.5 and 9.3.
Affected versions — including the latest
Huntress says all AhsayCBS versions "up through 10.3.4" are affected, and an October 8 update notes that 10.3.4 — the current latest release — is also affected, contrary to earlier NVD reporting that treated the issues as fixed. There is no patched version to move to. Huntress and BleepingComputer both report AhsayCBS had not responded to questions at publication. Until a fix ships, restrict access to the management interface.
Post-exploitation
After landing web shells, the operators pull an XMRig miner (edge.exe) and run it under a service named MicrosoftEdgeUpdateSvc using a modified copy of the NSSM service manager (msedge.exe). A PowerShell script, Taskgmr.ps1, which Huntress believes is AI-assisted, hides the mining: it stops the service when Task Manager opens, restarts it when Task Manager closes, and kills Task Manager outright at 6 p.m. local time or after it has been open more than an hour overnight. In at least one case certutil.exe fetched the vulnerable WinRing0x64.sys driver, a familiar bring-your-own-driver move to free up hardware for mining.
Detection artifacts
Huntress published indicators and four Sigma rules. The indicators, copied verbatim from the Huntress report:
IP addresses:
177.4.12[.]11 (AS140227 HKCICL-AS-AP Hong Kong)
38.60.252[.]110 (AS154177 LIGHT4-AS-AP Vietnam)
107.191.47[.]199 (AS20473 AS-VULTR France)
185.220.236[.]49 (AS38136 AKARI-NETWORKS-AS-AP Taiwan)
104.234.26[.]10 (AS134677 IDC-AS-AP United States)
123.202.208[.]37 (AS9269 HKBN-AS-AP Hong Kong)
Staging URLs:
hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/Taskgmr.ps1
hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/edge.exe
hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/msedge.exe
hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/config.json
hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/WinRing0x64.sys
Mining pool URL: xmr.kryptex[.]network:8029
Mining pool user: krxYMRN97D/creativejs
SHA256:
msedge.exe (modified NSSM): 05f69ae6b2b89c1c4dcf836bff032232f11bf0109f2b498e2345045d06139034
edge.exe (XMRig miner): 4dcb0202fe8b2d4d7b183764e38184cd6ed50132786cc7e7d1f7f4bce1dd6f3d
Taskgmr.ps1 (PowerShell): 481728a7c9c4c02be07051d9c1958d902ea6397ebb8952ab83944818e3d25d21
The four Sigma rules live in the Huntress threat-intel repository: unexpected child process from the AhsayCBS service, a fake Edge binary launched with a daemonized flag, the Task-Manager-aware PowerShell service control, and the WinRing0 driver download.
What to do today
- Restrict the AhsayCBS management interface to trusted IPs now. With no patch available, exposure reduction is the only control.
- Hunt for the indicators above and the named artifacts (
edge.exe,msedge.exe,Taskgmr.ps1,WinRing0x64.sys, theMicrosoftEdgeUpdateSvcservice). - If compromise is confirmed, rebuild the host from a known-good backup — Huntress warns of possible additional backdoors beyond the miner.
Context
A still-unpatched flaw in backup software, exploited within days of its CVE assignment (the IDs were published October 4), is the recurring edge-appliance story: management planes exposed to the internet, a vendor slow to confirm, and opportunistic miners first through the door. Treat the cryptominer as the noisy tenant, not the ceiling — unauthenticated SYSTEM RCE on a backup server is pre-ransomware real estate.