thehackernews.com 9 Oct 2026, 12:47 UTC

Hackers Exploit AhsayCBS Flaws to Deploy Hidden Crypto Miners

CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Available

THREAT actors are exploiting two recently disclosed flaws in the AhsayCBS backup utility to take remote control of affected systems, drop web shells, and deploy XMRig cryptocurrency miners that masquerade as the Microsoft Edge browser.

The flaws are CVE-2026-105133 (CVSS v4 score: 5.5) described as an improper authentication vulnerability in the checkSysPwd() function within com/ahsay/obs/api/ApiStructsAction[.]java, and CVE-2026-105134 (CVSS v4 score: 9.3) an operating system command injection vulnerability in the Replication Receiver component. Exploitation chains the two issues to bypass authentication and execute arbitrary commands. The CVEs were published on 4 October 2026.

Huntress reports that exploitation began on 7 October 2026 at 23:20 UTC, with threat actors achieving remote code execution on affected hosts. By 8 October 2026 at least five organisations were estimated to be affected. Post-exploitation activity includes reconnaissance, dropping web shells, and installing XMRig miners that disguise themselves as edge[.]exe, plus a PowerShell script (Taskgmr.ps1) launched via curl to drive mining.

The miners also incorporate AI-assisted elements and anti-analysis checks; they stop mining if Windows Task Manager is opened, and they terminate Task Manager after one hour overnight. In one observed incident, actors used certutil[.]exe to download a vulnerable driver (WinRing0x64[.]sys) to gain kernel-level access. Although the NVD advisories indicate resolution in version 10.3.4, Huntress states that AhsayCBS remains affected, effectively turning these into zero-days until patches are confirmed.

Practically, organisations should restrict AhsayCBS management interface web access to trusted IPs or require a VPN and search for signs of compromise.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline