Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

Threat actors are capitalizing on unpatched vulnerabilities in the AhsayCBS backup management platform to deploy malicious code and mine cryptocurrency. The affected organizations, at least five of which have been targeted, rely on managed service providers (MSPs) and system integrators to manage their backups.

AhsayCBS is a critical component for many businesses, used to store and recover sensitive data in case of disasters or cyber attacks. Unfortunately, the platform’s flaws are being exploited by attackers who chain two vulnerabilities together: CVE-2026-105133, an authentication bypass vulnerability with a publicly available exploit, and CVE-2026-105134, which allows for OS command injection.

The researchers at Huntress, a managed detection and response company, discovered that these security issues not only affect older versions of AhsayCBS but also the latest version, 10.3.4. This raises serious concerns about the platform’s security posture and the potential for widespread attacks. The attackers use the vulnerabilities to gain access to the system, deploy webshells, and mine cryptocurrency using tools like XMRig.

The malware used in these attacks is sophisticated and designed to evade detection. It uses a PowerShell script to conceal its activity by stopping and restarting services when Task Manager is opened or closed. This allows it to persist on the host without being detected. In one case, the attacker also deployed a vulnerable driver to unlock additional hardware resources for the miner.

The incident highlights the importance of regular security patching and vulnerability management. It’s essential that system administrators restrict access to the AhsayCBS management interface to trusted IP addresses only and investigate signs of compromise immediately. If a breach is confirmed, they should perform a full restore from a safe backup, as the attacker may have installed additional backdoors for prolonged persistence.

AhsayCBS has not yet responded to CyberNews.work’s request for comment on their plans to fix these vulnerabilities. Until a patch becomes available, system administrators must be vigilant and take proactive measures to protect themselves against these attacks. Huntress has provided indicators of compromise (IoCs) and Sigma rules to help defenders detect this activity.

This incident serves as a reminder that even the most critical infrastructure components can have security flaws that are exploited by attackers. It’s essential for organizations to stay informed about potential vulnerabilities and take proactive measures to protect themselves against these types of attacks.


Source: Bleeping Computer — 2026-10-09