Hackers hit unpatched Ahsay backup servers to mine crypto

Published

Attackers are breaking into internet-facing AhsayCBS servers, the management console for Ahsay's backup software, and turning them into cryptocurrency miners. Huntress reports that it began seeing exploitation at 23:20 UTC on October 7, with attackers gaining code execution as SYSTEM, the most powerful account on a Windows machine, without logging in first.

The stakes are higher than one server. AhsayCBS is used mainly by managed service providers and system integrators to run backups for their customers, so a compromised console sits close to a lot of other people's data.

Two bugs, chained, and no fix yet

Huntress says attackers are chaining two flaws identified on October 4. CVE-2026-105133 is a medium-severity improper authentication bug, which the attackers use to get past the login. CVE-2026-105134 is rated critical and sits in the console's Replication Receiver component, where it allows unauthenticated remote code execution. In some intrusions the attackers configured a malicious receiver and dropped a JSP web shell, a small backdoor page, into the directory the application serves.

The worst news came in an update the same evening. Huntress had initially reported that version 10.3.4 was safe, but after further testing it says AhsayCBS versions through 10.3.4 are affected. It has shared its research with Ahsay, and until a patch exists there is no version to upgrade to.

A miner that hides from Task Manager

After getting in, the attackers used the AhsayCBS service process (cbssvcX64.exe) to download files from an Alibaba Cloud storage bucket into the Temp folder. The payload is XMRig, a legitimate Monero miner, renamed edge.exe to pass as Microsoft Edge. A modified copy of the NSSM service utility, renamed msedge.exe, keeps it running through a Windows service called MicrosoftEdgeUpdateSvc, chosen to resemble the real Edge updater.

A PowerShell script, Taskgmr.ps1, which Huntress believes was written with AI help judging by its comments, stops the mining service whenever Task Manager is open and restarts it when it closes. In one case the attackers also pulled down WinRing0x64.sys, a legitimate but vulnerable kernel driver, apparently to give the miner low-level hardware access rather than to disable security tools. The miner, like the Linux cryptojacking crews we covered in July, is cheap to run and easy to monetize, which is why exposed servers attract it so quickly.

Lock the console behind a VPN and look for intruders

Until Ahsay ships a fix, Huntress recommends limiting access to the AhsayCBS management interface to trusted IP addresses or putting it behind a VPN. Any server showing the indicators below should be fully re-imaged from a trusted backup, because attackers may have left secondary backdoors. Huntress has also published four Sigma rules for this campaign, including one that flags any unexpected child process spawned by the AhsayCBS service.

Key indicators from the report:

This round of attackers wanted CPU cycles. The next group to find an exposed backup console with SYSTEM access may want the backups themselves, so the access restriction is worth applying today rather than waiting for the patch.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Detection coverage

Read the full analysis on IntelFusions