Threat actors are actively exploiting two vulnerabilities — one rated critical, one medium — in the AhsayCBS backup management platform that remain unpatched at the time of reporting. Confirmed intrusions show attackers using the flaws to drop webshells on exposed backup servers and, in follow-on stages, deploy cryptocurrency miners that consume host resources while establishing persistence.
This should alarm every defender for one specific reason: backup infrastructure is your last line of defense in a ransomware event, and it is also a crown-jewel target. AhsayCBS servers typically hold credentials for every protected endpoint, hypervisor, cloud tenant, and SaaS workload in scope. An attacker with a webshell on your AhsayCBS host doesn't just have cryptomining compute — they have a staging point to enumerate, corrupt, or exfiltrate your backup catalog, and potentially a pivot into every system the backup server can authenticate to. Cryptominers are frequently a secondary payload; the webshell is the real prize, and it stays behind after the miner is cleaned up.
Because no vendor fix is currently available, detection engineering and compensating controls are your only options. This post gives you both.
Technical Analysis
Affected Product
- Product: AhsayCBS (Ahsay Cloud Backup Suite) — a centralized backup server/management console used by MSPs and enterprises to manage backup agents across Windows, Linux, macOS, VMware/Hyper-V, Microsoft 365, and cloud storage targets.
- Architecture relevant to defense: AhsayCBS ships with an embedded Apache Tomcat-based web console (commonly listening on TCP 8080/8443) running under a Java process (
java.exe/java), typically as thecbshomeservice (Windows) or a systemd unit (Linux). Default install paths areC:\Program Files\AhsayCBS(Windows) and/usr/local/cbsor/opt/cbs(Linux). - Severity: One critical flaw and one medium-severity flaw, both unpatched as of this report and actively exploited in the wild.
Attack Chain (Defender's View)
Based on the reported intrusions, the observable kill chain is:
- Initial access: The attacker targets an internet-reachable AhsayCBS management interface. Exploitation requires network reachability to the console — meaning any org that exposed the web UI directly to the internet (a depressingly common MSP pattern for remote management) is exposed.
- Code execution / file write: Successful exploitation yields the ability to write arbitrary files into the Tomcat web application directories and/or execute commands in the security context of the AhsayCBS service account (frequently
SYSTEMon Windows orroot/cbsservice account on Linux — Tomcat-based backup consoles are notorious for over-privileged service contexts). - Webshell deployment: Attackers drop JSP webshells into web-accessible directories under the AhsayCBS web root (e.g., paths under
webapps/). This gives durable, restart-resistant remote access independent of the original vulnerability. - Post-exploitation: From the webshell, operators download and execute secondary payloads — confirmed as XMRig-style cryptocurrency miners in this campaign — and enumerate the host for credentials, backup configurations, and lateral movement opportunities.
Exploitation Status
- Status: Confirmed active in-the-wild exploitation.
- Patch status: No vendor patch available at time of publication. Treat this as an N-day-under-active-exploitation with zero vendor remediation — functionally equivalent to a zero-day from a defensive planning standpoint.
- CISA KEV: Monitor CISA's Known Exploited Vulnerabilities catalog; actively exploited unpatched flaws in backup platforms are strong KEV candidates, which would impose remediation deadlines on federal agencies and signal prioritization for everyone else.
Why Backup Servers Are the Worst Possible Host for This
In 15 years of IR work, the pattern is consistent: whoever controls the backup server controls the recovery timeline. AhsayCBS stores:
- Encryption keys and passphrases for backup sets
- Credentials for vCenter/ESXi, Hyper-V, NAS targets, cloud storage (S3, Azure Blob, Wasabi), and SaaS tenants (M365/Google Workspace)
- Network topology of every protected asset
A cryptominer is the least damaging outcome. The webshell that preceded it is a durable foothold an operator can monetize later — by selling access to a ransomware affiliate who will delete your backups before encrypting production. Responders should treat every confirmed AhsayCBS webshell as a potential precursor to a full intrusion, not a commodity miner infection.
Detection & Response
The detections below target the two most reliable observables in this campaign: (1) the AhsayCBS Java/Tomcat process spawning shells or script interpreters it has no business spawning, and (2) JSP webshell artifacts written into the Tomcat web application tree. Miner deployment is downstream of both, so catch the foothold, not just the payload.
Sigma Rules
---
title: AhsayCBS Java Process Spawning Shell or Script Interpreter
id: 3f8a1c2e-7b4d-4e91-a2c6-9d5f0b8e3a71
status: experimental
description: Detects the AhsayCBS/Tomcat Java process spawning command shells or script interpreters, consistent with webshell post-exploitation activity reported in the AhsayCBS exploitation campaign.
references:
- https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/02/10
tags:
- attack.execution
- attack.t1059
- attack.t1505.003
logsource:
category: process_creation
product: windows
detection:
selection_parent:
ParentImage|endswith:
- '\java.exe'
- '\javaw.exe'
- '\tomcat.exe'
selection_parent_path:
ParentImage|contains:
- '\AhsayCBS\'
- '\Ahsay\'
selection_child:
Image|endswith:
- '\cmd.exe'
- '\powershell.exe'
- '\pwsh.exe'
- '\wscript.exe'
- '\cscript.exe'
- '\wmic.exe'
- '\certutil.exe'
- '\bitsadmin.exe'
- '\mshta.exe'
- '\curl.exe'
- '\rundll32.exe'
condition: selection_parent and selection_parent_path and selection_child
falsepositives:
- Rare. AhsayCBS legitimately invokes some helper scripts during backup jobs, but shells spawned directly from the Tomcat Java process outside scheduled backup windows warrant immediate triage.
level: high
---
title: JSP Webshell File Written to AhsayCBS Tomcat Web Directory
id: 8c2e5a91-4d6b-4f37-b8a2-1e9c7d3f5a06
status: experimental
description: Detects creation of JSP files in AhsayCBS Tomcat web application directories, a key indicator of webshell deployment following exploitation of the unpatched AhsayCBS vulnerabilities.
references:
- https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/
- https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/02/10
tags:
- attack.persistence
- attack.t1505.003
logsource:
category: file_event
product: windows
detection:
selection_path:
TargetFilename|contains:
- '\AhsayCBS\webapps\'
- '\AhsayCBS\web\'
- '\AhsayCBS\tomcat\'
selection_ext:
TargetFilename|endswith:
- '.jsp'
- '.jspx'
- '.war'
condition: selection_path and selection_ext
falsepositives:
- Legitimate AhsayCBS version upgrades write JSP files. Correlate with patch/upgrade maintenance windows; any JSP write outside a vendor upgrade is malicious until proven otherwise.
level: critical
---
title: Suspicious Child Process of AhsayCBS Service on Linux
id: 1b7d4e26-9a3c-4f58-8d1b-6c2a5e7f9b40
status: experimental
description: Detects the AhsayCBS Java process on Linux spawning shells, downloaders, or common miner staging tools, consistent with the reported post-exploitation chain.
references:
- https://www.bleepingcomputer.com/news/security/unpatched-ahsaycbs-flaws-exploited-to-deploy-webshells-mine-crypto/
- https://attack.mitre.org/techniques/T1059/004/
author: Security Arsenal
date: 2026/02/10
tags:
- attack.execution
- attack.t1059.004
- attack.t1105
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- '/java'
selection_child:
Image|endswith:
- '/sh'
- '/bash'
- '/dash'
- '/curl'
- '/wget'
- '/chmod'
- '/crontab'
- '/base64'
- '/python'
- '/python3'
- '/perl'
condition: selection_parent and selection_child
falsepositives:
- AhsayCBS invokes helper utilities during backup/restore jobs. Tighten by correlating with backup schedule and by inspecting full command lines for download cradles or miner flags (stratum, xmrig, --donate-level, hugepages).
level: high
KQL — Microsoft Sentinel / Defender
This query hunts the process-tree anomaly (AhsayCBS Java/Tomcat spawning shells) and the webshell file-write artifact together. It works against Defender for Endpoint telemetry and against Syslog-ingested Linux hosts via Syslog.
// Hunt: AhsayCBS exploitation — webshell writes + suspicious child processes
let suspiciousChildren = dynamic(["cmd.exe","powershell.exe","pwsh.exe","wscript.exe","cscript.exe","wmic.exe","certutil.exe","bitsadmin.exe","mshta.exe","curl.exe","rundll32.exe","sh","bash","wget","curl","crontab","base64"]);
let procHits = DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName in~ ("java.exe","javaw.exe","tomcat.exe","java")
or InitiatingProcessCommandLine has_any ("AhsayCBS","ahsay","cbs")
| where FileName in~ (suspiciousChildren)
or ProcessCommandLine has_any ("stratum","xmrig","donate-level","hugepages","/dev/tcp","IEX","Invoke-Expression","FromBase64String")
| project TimeGenerated, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, AccountName, ReportId;
let fileHits = DeviceFileEvents
| where TimeGenerated > ago(14d)
| where FolderPath has_any ("AhsayCBS\\webapps","AhsayCBS\\web","AhsayCBS\\tomcat","/usr/local/cbs/","/opt/cbs/")
| where FileName endswith ".jsp" or FileName endswith ".war"
| where ActionType in ("FileCreated","FileModified","FileRenamed")
| project TimeGenerated, DeviceName, FileName, FolderPath, InitiatingProcessFileName, InitiatingProcessCommandLine, ActionType, SHA256, ReportId;
union procHits, fileHits
| order by TimeGenerated desc
For Sentinel environments ingesting Linux via Syslog, add a parallel hunt for miner network behavior — outbound connections from the AhsayCBS host to common mining pool ports (3333, 4444, 5555, 7777, 14444) are a high-fidelity signal when the source process is java or an unknown binary in /tmp or /var/tmp:
// Hunt: Miner staging artifacts and pool connections from AhsayCBS hosts (Syslog/CEF)
Syslog
| where TimeGenerated > ago(7d)
| where ProcessName has_any ("java","sh","bash")
| where SyslogMessage has_any ("/usr/local/cbs","/opt/cbs","stratum","xmrig","cryptonight","/tmp/.", "chmod 777")
| project TimeGenerated, Computer, ProcessName, SyslogMessage
| order by TimeGenerated desc
Velociraptor VQL
Use this hunt artifact across your AhsayCBS fleet to sweep for webshell artifacts, suspicious Java child processes, and miner staging directories in one pass:
-- AhsayCBS Compromise Sweep: webshells, suspicious child processes, miner staging
-- Deploy as a hunt scoped to servers running AhsayCBS
LET webshells = SELECT FullPath, Size, Mtime, Btime,
read_file(filename=FullPath, length=4096) AS Head
FROM glob(globs=[
'C:/Program Files/AhsayCBS/webapps/**/*.jsp',
'C:/Program Files/AhsayCBS/web/**/*.jsp',
'/usr/local/cbs/webapps/**/*.jsp',
'/opt/cbs/webapps/**/*.jsp'
])
WHERE Mtime > now() - 1209600 -- modified in last 14 days
LET suspicious_procs = SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE CommandLine =~ '(?i)(stratum|xmrig|cryptonight|donate-level|/dev/tcp|base64 -d|certutil -decode)'
OR (Name =~ '(?i)^(cmd|powershell|pwsh|sh|bash|curl|wget)$'
AND CommandLine =~ '(?i)(http://|https://|/tmp/|%TEMP%|appdata)')
LET tmp_staging = SELECT FullPath, Size, Mtime
FROM glob(globs=['/tmp/*','/var/tmp/*','C:/Windows/Temp/*.exe','C:/Users/Public/*.exe'])
WHERE Mtime > now() - 1209600 AND Size > 100000
SELECT * FROM webshells
Run the three selectors as separate artifacts (webshells, suspicious_procs, tmp_staging) if your deployment prefers discrete hunts; the webshell glob alone — JSP files under the AhsayCBS web root modified in the last 14 days — is the single highest-value sweep.
Remediation & Hardening Script
Since no patch exists, this PowerShell script performs the three things you can actually do today: (1) audit the Tomcat web directories for webshell artifacts, (2) enumerate the AhsayCBS process tree and network listeners for miner indicators, and (3) apply compensating controls — restricting the management console to localhost or a management VLAN and flagging unexpected outbound listeners.
#Requires -RunAsAdministrator
# AhsayCBS Emergency Audit & Hardening — run on every AhsayCBS host
# 1) Webshell sweep, 2) Process/network triage, 3) Compensating firewall controls
$ErrorActionPreference = 'SilentlyContinue'
$report = "C:\Windows\Temp\AhsayCBS_Audit_$(Get-Date -Format 'yyyyMMdd_HHmmss').txt"
"=== AhsayCBS Compromise Audit $(Get-Date) ===" | Out-File $report
# --- 1. Webshell sweep: JSP/WAR files modified in last 30 days under AhsayCBS ---
$cbsRoot = 'C:\Program Files\AhsayCBS'
"`n[1] Recent JSP/WAR files under $cbsRoot" | Out-File $report -Append
Get-ChildItem -Path $cbsRoot -Recurse -Include *.jsp,*.jspx,*.war -File |
Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-30) } |
Select-Object FullName, LastWriteTime, Length |
Format-Table -AutoSize | Out-String | Out-File $report -Append
# --- 2. Process tree triage: shells/miners spawned under java/tomcat ---
"`n[2] Suspicious child processes of java/tomcat" | Out-File $report -Append
$javaProcs = Get-CimInstance Win32_Process | Where-Object { $_.Name -match '^(java|javaw|tomcat).*\.exe$' }
foreach ($jp in $javaProcs) {
Get-CimInstance Win32_Process | Where-Object { $_.ParentProcessId -eq $jp.ProcessId } |
Where-Object { $_.Name -match 'cmd|powershell|pwsh|wscript|cscript|wmic|certutil|bitsadmin|mshta|curl|rundll32' } |
Select-Object Name, ProcessId, CommandLine |
Format-List | Out-String | Out-File $report -Append
}
# Miner string scan across running processes
"`n[3] Processes with miner indicators in command line" | Out-File $report -Append
Get-CimInstance Win32_Process |
Where-Object { $_.CommandLine -match 'stratum|xmrig|cryptonight|donate-level|hugepages' } |
Select-Object Name, ProcessId, ExecutablePath, CommandLine |
Format-List | Out-String | Out-File $report -Append
# Outbound listeners/connections on common pool ports
"`n[4] Connections to common mining pool ports" | Out-File $report -Append
Get-NetTCPConnection -State Established |
Where-Object { $_.RemotePort -in 3333,4444,5555,7777,14444 } |
Select-Object LocalAddress,LocalPort,RemoteAddress,RemotePort,OwningProcess |
Format-Table -AutoSize | Out-String | Out-File $report -Append
# --- 5. COMPENSATING CONTROL: restrict AhsayCBS console (8080/8443) to mgmt subnet ---
# Adjust -RemoteAddress to YOUR management network before enabling.
$mgmtSubnet = '10.10.50.0/24'
"`n[5] Applying firewall restriction on AhsayCBS console ports to $mgmtSubnet" | Out-File $report -Append
New-NetFirewallRule -DisplayName 'AhsayCBS Console - Mgmt Only (8080)' `
-Direction Inbound -Protocol TCP -LocalPort 8080 -RemoteAddress $mgmtSubnet -Action Allow | Out-Null
New-NetFirewallRule -DisplayName 'AhsayCBS Console - Mgmt Only (8443)' `
-Direction Inbound -Protocol TCP -LocalPort 8443 -RemoteAddress $mgmtSubnet -Action Allow | Out-Null
New-NetFirewallRule -DisplayName 'AhsayCBS Console - Block All Else (8080)' `
-Direction Inbound -Protocol TCP -LocalPort 8080 -Action Block | Out-Null
New-NetFirewallRule -DisplayName 'AhsayCBS Console - Block All Else (8443)' `
-Direction Inbound -Protocol TCP -LocalPort 8443 -Action Block | Out-Null
"`nAudit complete. Review $report and escalate any hits to IR immediately." | Out-File $report -Append
Write-Host "Done — report at $report"
On Linux AhsayCBS hosts, the equivalent triage one-liner set: find /usr/local/cbs -name '*.jsp' -mtime -14 -ls, ps -ef --forest | grep -A2 java, ss -tulpn | grep -E '3333|4444|5555|7777|14444', and crontab -l plus ls -la /etc/cron.d /var/spool/cron (miner persistence frequently lands in cron).
Remediation
Because there is no vendor patch, your remediation strategy is containment, hardening, and monitoring until Ahsay ships a fix:
- Remove the console from the internet — today. This is the single highest-impact action. The AhsayCBS management interface should never be internet-reachable. Place it behind a VPN or restrict inbound 8080/8443 to a dedicated management VLAN or jump host. If you are an MSP exposing customer consoles for "convenience," that model just became a liability you must retire.
- Sweep for webshells before assuming you're clean. Exploitation predates your awareness. Run the webshell glob/VQL sweep above across every AhsayCBS host. Any JSP file in the web tree not attributable to a documented vendor upgrade is an incident — isolate the host and treat it as a full intrusion, not a malware cleanup.
- Credential rotation on any confirmed-compromised host. If a webshell is found, assume theft of: AhsayCBS admin credentials, backup set encryption keys, hypervisor credentials (vCenter/Hyper-V), cloud storage keys (S3/Azure/Wasabi), and M365/Google Workspace service principals. Rotate all of them. This is painful and non-optional.
- Verify backup integrity. Check for deleted or modified backup sets, new/unknown admin or user accounts in the AhsayCBS console, and unexpected changes to retention policies or encryption settings. Attackers pre-positioning for ransomware routinely degrade backups weeks in advance.
- Egress filtering. Block outbound connections from the AhsayCBS host to anything other than required backup destinations and Ahsay update/licensing endpoints. This neuters both miner pool connectivity and most webshell download cradles.
- Service account least privilege. If the AhsayCBS service runs as SYSTEM/root (default on many installs), evaluate dropping it to a dedicated service account with only the permissions backup operations require. This limits blast radius from the next flaw — and there will be a next flaw.
- Monitor Ahsay's advisory channels and CISA KEV. Apply the vendor patch within 24-48 hours of release; given confirmed exploitation, this will be a drop-everything patch event. If CISA adds these flaws to KEV, federal civilian agencies will face a binding remediation deadline — use that as your internal forcing function even if you're not BOD 22-01-bound.
- Long term: treat backup infrastructure as Tier 0. Backup consoles belong in the same protection tier as domain controllers: dedicated management network, no internet exposure, enhanced logging, and inclusion in threat hunting scope. This campaign is the latest proof that attackers understand the leverage backup servers provide — your architecture should reflect that you understand it too.
Related Resources
Security Arsenal Alert Triage Automation AlertMonitor Platform Book a SOC Assessment platform Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.