Full Report
Threat actors are exploiting AhsayCBS flaws, including CVE-2026-105133 and CVE-2026-105134, to deploy webshells and XMRig cryptominers. Update to 10.3.4 and restrict access now.
Analysis Summary
# Incident Report: Exploitation of AhsayCBS RCE Vulnerabilities
## Executive Summary
In October 2026, threat actors began mass exploitation of two vulnerabilities in the AhsayCBS backup management console (CVE-2026-105133 and CVE-2026-105134). The attacks resulted in unauthenticated remote code execution (RCE), allowing attackers to deploy webshells and XMRig cryptominers. The incident highlights a trend of using AI-assisted scripting to evade local detection mechanisms.
## Incident Details
- **Discovery Date:** October 7, 2026 (23:20:15 UTC)
- **Incident Date:** October 7 – October 8, 2026 (Active exploitation)
- **Affected Organization:** Multiple (5 organizations confirmed by Huntress as of Oct 8)
- **Sector:** Managed Service Providers (MSPs), System Integrators
- **Geography:** Global / Distributed
## Timeline of Events
### Initial Access
- **Date/Time:** October 7, 2026, 23:20:15 UTC
- **Vector:** Exploitation of unauthenticated API endpoints.
- **Details:** Attackers exploited CVE-2026-105134 (Replication Receiver component) and CVE-2026-105133 (Improper Authentication in `checkSysPwd`) to gain access to the NT AUTHORITY/SYSTEM account.
### Lateral Movement
- **Details:** Following initial access, attackers conducted internal reconnaissance and environment discovery. Specific lateral movement between servers was not detailed in the initial report, but the focus was on establishing a foothold on the management server.
### Data Exfiltration/Impact
- **Details:** The primary impact was unauthorized resource consumption. Attackers deployed XMRig cryptominers (masqueraded as Microsoft Edge) to utilize host CPU resources for illicit cryptocurrency mining.
### Detection & Response
- **Discovery:** Detected by Huntress via behavioral monitoring of the AhsayCBS process.
- **Response:** Notification of affected parties, research into the vulnerability range (confirming version 10.3.4 is also vulnerable), and coordination with the vendor.
## Attack Methodology
- **Initial Access:** Unauthenticated RCE via `/rps/api/json/UpdateReceivers.do`.
- **Persistence:** Deployment of webshells to maintain access to the web server.
- **Privilege Escalation:** Not required; the vulnerability inherently grants NT AUTHORITY/SYSTEM permissions.
- **Defense Evasion:**
- Masquerading malicious binaries as legitimate processes (`msedge.exe`).
- Using AI-assisted PowerShell scripts to monitor and terminate Windows Task Manager if left open during "off-hours" to prevent manual discovery by admins.
- **Discovery:** Reconnaissance via standard system commands and AI-generated enumeration scripts.
- **Impact:** Deployment of XMRig cryptominers for resource hijacking.
## Impact Assessment
- **Financial:** Increased electricity and hardware wear; potential loss of billable hours for MSPs remediating the issue.
- **Data Breach:** None reported, though full system access makes data theft a high-risk possibility.
- **Operational:** High; compromise of a backup management server threatens the integrity of the entire backup infrastructure.
- **Reputational:** Moderate for MSPs whose primary role is to secure and back up client data.
## Indicators of Compromise
- **Network:** Connections to known mining pools (defanged: `xmr-eu1.nanopool[.]org`).
- **Files:**
- `msedge.exe` (located in non-standard directories like `/temp/` or Ahsay application folders).
- AI-generated PowerShell scripts monitoring `taskmgr.exe`.
- **Behavior:** AhsayCBS service (`java.exe`) spawning `cmd.exe` or `powershell.exe` to execute `curl` or `certutil`.
## Response Actions
- **Containment:** Restrict access to the AhsayCBS management interface (port 443/80/8443) to trusted IPs only.
- **Eradication:** Identify and remove webshells, kill malicious `msedge.exe` (miner) processes, and delete associated persistence scripts.
- **Recovery:** Current versions (including 10.3.4) are reported as vulnerable; until a specific patch is verified, continuous monitoring is required.
## Lessons Learned
- **AI-Augmented Threats:** Attackers are now using "vibe-coding" or AI-assisted scripting to create highly specific defense evasion tools (like the Task Manager killer).
- **Vulnerability Misidentification:** Early reports suggested 10.3.4 was safe; however, active exploitation proved that versions previously thought to be patched remained vulnerable.
## Recommendations
- **Immediate Action:** Place the AhsayCBS management console behind a VPN or IP whitelist.
- **Update:** Monitor Ahsay official channels for a verified patch exceeding version 10.3.4.
- **Audit:** Inspect web directories of AhsayCBS for unauthorized `.jsp` or `.php` files (potential webshells).
- **Monitoring:** Implement EDR/MDR alerts for any child processes spawned by the Ahsay backup service.