As reported by The Hacker News, threat actors are actively exploiting a chained vulnerability in AhsayCBS backup software to deploy XMRig cryptocurrency miners disguised as Microsoft Edge. What makes this campaign particularly concerning is that even systems running the vendor's recommended "fixed" version (10.3.4) remain vulnerable, effectively rendering these zero-days with no available patch.
Vulnerability Breakdown
| CVE | CVSS v4 | Type | Component | Status |
|---|---|---|---|---|
| CVE-2026-105133 | 5.5 (Medium) | Improper Authentication | checkSysPwd() in ApiStructsAction.java | Unpatched in 10.3.4 |
| CVE-2026-105134 | 9.3 (Critical) | OS Command Injection | Replication Receiver | Unpatched in 10.3.4 |
The attack chain is straightforward but devastating: CVE-2026-105133 bypasses authentication on the management interface, and CVE-2026-105134 then provides arbitrary command execution. The CVSS v4 9.3 rating on the command injection flaw accurately reflects the severity — this is a full remote code execution primitive accessible to any unauthenticated attacker who can reach the AhsayCBS interface.
Why This Matters Beyond Cryptojacking
While the immediate payload is XMRig mining, defenders should not dismiss this as a nuisance-level threat. Several aspects of the post-exploitation tradecraft warrant elevated concern:
WinRing0x64.sys signals intent for kernel-level access, which could enable defense evasion, privilege escalation, and deeper persistence.The fact that the vendor's stated patched version (10.3.4) is itself vulnerable means there is currently no remediation path through upgrading. Organizations must rely on compensating controls.
Who Is at Risk
Any organization running AhsayCBS with its management interface or Replication Receiver component exposed to the network is at immediate risk. Backup infrastructure is particularly high-value because it often holds credentials, network topology data, and business-critical data — making it a prime target for both cryptojacking and follow-on extortion attacks. Managed service providers using AhsayCBS across multiple customer environments face amplified risk due to potential multi-tenant compromise.
Shield53 Recommendations
Immediate Actions
- Network segmentation: Immediately restrict access to the AhsayCBS management interface and Replication Receiver ports. Allow only from explicitly trusted backup controller IPs via firewall rules or ACLs. No internet exposure under any circumstances.
- WAF/reverse proxy: Place AhsayCBS behind a reverse proxy or WAF capable of filtering requests to
ApiStructsActionand the Replication Receiver endpoints. Apply rate limiting and request validation. - Hunt for compromise: Search for processes named
edge.exerunning from non-standard directories, PowerShell scripts namedTaskgmr.ps1, andWinRing0x64.sysin TEMP folders. Checkcertutil.exeusage in process logs for download activity. - Monitor for web shells: Audit web-accessible directories within the AhsayCBS installation for unexpected JSP, ASP, or PHP files. Review file integrity monitoring data if available.
Detection Guidance
- SIEM rule: Alert on
certutil.exe -urlcache -split -fcommands originating from the AhsayCBS service account context. - EDR hunt: Query for child processes of the AhsayCBS Java process spawning
cmd.exe,powershell.exe, orcurl.exe. - Network detection: Monitor for outbound XMRig pool connections (common ports 3333, 4444, 5555, 7777) from backup server infrastructure.
Longer-Term Considerations
- Evaluate whether AhsayCBS can be isolated in a dedicated network zone with no outbound internet access, using a jump host for administration.
- Engage with the vendor for a definitive patch timeline and demand transparency on the 10.3.4 discrepancy.
- Review backup infrastructure security posture broadly — backup systems are increasingly the first target in ransomware operations.
The absence of a working patch transforms this from a standard patch-priority exercise into an incident-readiness scenario. Treat any internet-exposed AhsayCBS instance as potentially compromised and initiate threat hunting immediately.