Overview
Attackers are exploiting two vulnerabilities in AhsayCBS, a backup management platform used by organisations, managed service providers and system integrators, to gain unauthorised access, deploy web shells and install cryptocurrency miners. Tracked as CVE-2026-105133 and CVE-2026-105134, the vulnerabilities can be chained to bypass authentication and execute commands remotely. The campaign demonstrates a concerning reality: infrastructure designed to protect enterprise data can itself become an entry point for attackers.
From Authentication Bypass to System-Level Access
The attack chain combines two weaknesses. CVE-2026-105133 affects authentication logic, while CVE-2026-105134 introduces operating-system command injection in the Replication Receiver component. Together, these vulnerabilities can allow attackers to move from unauthenticated access to remote code execution. Huntress reported exploitation beginning on 7 October 2026, with five organisations targeted by the following day. Once inside, attackers deployed web shells to maintain access and installed XMRig cryptocurrency miners. The immediate objective appears to be generating cryptocurrency using compromised computing resources, but the presence of web shells creates a broader concern: access could persist beyond the initial mining activity.
When Malware Pretends to Be Microsoft Edge
The campaign also illustrates how attackers disguise malicious activity within seemingly legitimate Windows processes and services. The XMRig miner was named edge.exe, while a supporting executable and Windows service were configured to resemble Microsoft Edge’s legitimate update components. This naming strategy can make suspicious activity harder to distinguish from normal operations when monitoring relies too heavily on process names. Attackers also deployed a PowerShell script that monitored Windows Task Manager and stopped the mining service when Task Manager was open. The script could also terminate Task Manager under specific conditions, actively interfering with an administrator’s ability to investigate unusual resource consumption. In one incident, attackers downloaded the vulnerable WinRing0 driver, apparently to provide the miner with low-level hardware access. The result was more than a simple unwanted application: it was a coordinated effort to establish persistence, conceal activity and maximise resource usage.
The Backup Platform Is Part of the Security Boundary
AhsayCBS centralises important backup administration functions, making its management interface a sensitive component of the enterprise environment. Compromise of such a system deserves particular attention because backup infrastructure supports business continuity and disaster recovery. The immediate priority is to restrict management access to trusted IP addresses or require VPN connectivity, rather than exposing the administrative interface directly to the internet. The patch situation also requires care. Huntress subsequently reported that version 10.3.4 was affected, contradicting earlier vulnerability information. Organisations should therefore follow the latest vendor and incident-response guidance rather than assume that installing this version resolves the exposure. Where compromise is suspected, investigation must extend beyond removing the miner. Web shells, persistence mechanisms and secondary backdoors must be considered. Huntress recommends rebuilding affected hosts from a trusted backup when its indicators of compromise are found.
Expert in the Cloud Insight
Backup infrastructure is not simply a storage destination. It is a privileged management layer that helps determine whether an organisation can recover when systems fail or are attacked. A security platform cannot be treated as trusted merely because its purpose is protection. Its own access paths, management interfaces and persistence mechanisms must be secured to the same standard as the systems it protects.
Leave a Reply