Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge

Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners.

Details of the flaws are below -

  • CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java" component.
  • CVE-2026-105134 (CVSS v4 score: 9.3) - An operating system command injection vulnerability in the Replication Receiver component.

A remote attacker could chain the two vulnerabilities to bypass authentication and execute arbitrary commands on affected systems. It's worth noting that CVE identifiers for these flaws were not published until October 4, 2026.

According to Huntress, exploitation efforts aimed at the two flaws began on October 7, 2026, at 11:20 p.m. UTC, with unidentified threat actors weaponizing them to achieve remote code execution on impacted hosts. As of October 8, 2026, five organizations targeted are estimated to have been affected by these flaws.

"Post-exploitation, threat actors are conducting reconnaissance, dropping web shells, planting XMRig cryptominers masquerading as Microsoft Edge, and more," the cybersecurity company said. "They also dropped what appears to be an AI-assisted PowerShell script that monitors the Windows Task Manager and shuts it down if it remains open for too long in the middle of the night."

The cryptocurrency miners have been found to impersonate the Microsoft Edge browser by using the name "edge.exe" to fly under the radar. Also dropped is a PowerShell script ("Taskgmr.ps1") that facilitates cryptomining operations after it's launched via curl.

The script, which is suspected to be written with assistance from an artificial intelligence (AI) tool, packs in anti-analysis checks that stop the mining activity as soon as a victim opens the Windows Task Manager app. It's also configured to terminate the Task Manager at 6 p.m. if it has been left open for more than one hour overnight.

Although the advisories published in the National Vulnerability Database (NVD) state that the issues have been addressed in the latest version of the software (10.3.4), Huntress has since revealed that it's also impacted, essentially turning them to zero-days.

In at least one incident, the threat actors are said to have used the built-in "certutil.exe" binary to download a legitimate-but-vulnerable driver ("WinRing0x64.sys") to the TEMP folder, likely with the aim of gaining kernel-level access to the underlying hardware and optimizing the mining process.

In the absence of a patch, users are recommended to limit access to the management interface and hunt for signs of compromise.

"Organizations should restrict AhsayCBS management interface web access, as the exploit targets the externally accessible web app service on the host," Huntress said. "Access should be limited to trusted IP addresses only or require VPN."

Dive deeper

Free tools to verify and analyze what this article covers:

source: TheHackerNews