Back to Intelligence

CVE-2026-105133: AhsayCBS Improper Authentication Exploited to Deploy XMRig Miners — Detection and Remediation Guide

SA
Security Arsenal Team
October 9, 2026
12 min read

Backup infrastructure is one of the highest-value targets in any environment — it holds copies of everything, runs with elevated privileges, and is frequently excluded from the same hardening scrutiny applied to production workloads. This week, that reality is on full display: threat actors are actively exploiting a pair of recently disclosed flaws in the AhsayCBS backup utility, including CVE-2026-105133 (CVSS v4: 5.5), an improper authentication vulnerability, to seize control of exposed backup servers, drop web shells for persistent access, and deploy XMRig cryptocurrency miners masquerading as the Microsoft Edge browser.

If your organization runs AhsayCBS — or if you are an MSP/MSSP whose clients do — treat this as an active-compromise scenario, not a patching ticket. The exploitation is confirmed in the wild, the post-exploitation tradecraft (web shells + miner masquerading) indicates hands-on actors rather than automated worms, and backup servers compromised at the authentication layer should be assumed fully breached.

Technical Analysis

The Vulnerability: CVE-2026-105133

  • Product affected: AhsayCBS (Ahsay Cloud Backup Suite) — the centralized backup server component used by enterprises and MSPs to manage backups for endpoints, servers, databases, and cloud workloads. AhsayCBS is Java-based and runs on both Windows and Linux.
  • CVE: CVE-2026-105133
  • CVSS v4 score: 5.5 (Medium) — do not let the moderate score lull you. A CVSS 5.5 that grants unauthenticated attackers a path to code execution on an internet-reachable backup server is operationally critical.
  • Root cause: An improper authentication weakness in the checkSysPwd() function within com/ahsay/obs/api/ApiStructsAction.java. The vulnerable code path is part of the AhsayCBS API action handler, meaning the flaw is reachable through the product's web/API interface — the same interface administrators expose for remote backup management, and the same interface attackers can probe directly.

The checkSysPwd() function is intended to validate a system-level password before permitting privileged API operations. Because the validation logic is flawed, an attacker can invoke protected API actions without valid credentials. In the observed campaign, this is being chained with a second, recently disclosed AhsayCBS flaw to move from authentication bypass to full device control.

Observed Attack Chain

Based on the in-the-wild activity, the intrusion flow looks like this:

  1. Reconnaissance — Attackers scan for exposed AhsayCBS web consoles/API listeners (commonly on the product's default management ports).
  2. Authentication bypass — CVE-2026-105133 is triggered against the vulnerable API endpoint, defeating the checkSysPwd() check.
  3. Web shell deployment — With API-level control, the actors write web shells into the AhsayCBS web application directory structure. This gives them durable, request-driven command execution that survives service restarts.
  4. Payload delivery — The web shell is used to download and execute XMRig, the well-known Monero miner.
  5. Masquerading — The miner binary is renamed and presented as Microsoft Edge (e.g., an msedge.exe-style filename or a path mimicking the browser) to evade casual process review and blend into host telemetry.

Why the Masquerade Matters for Defenders

Renaming a miner to look like a browser process is a cheap but effective trick. It defeats:

  • Helpdesk-style triage that eyeballs Task Manager.
  • Allowlist rules keyed on process name rather than full path and signer.
  • SOC queries that filter out "known-good" process names like msedge.exe.

The tell is almost always path and signer: legitimate Microsoft Edge runs from C:\Program Files (x86)\Microsoft\Edge\Application\ (or the per-user equivalent) and is signed by Microsoft Corporation. An msedge.exe running from %TEMP%, %APPDATA%, C:\ProgramData\, or the Ahsay installation tree — unsigned and holding outbound connections to mining pools — is malicious until proven otherwise.

Exploitation Status

  • Confirmed active exploitation in the wild. This is not a theoretical or PoC-only issue.
  • Post-exploitation includes interactive tradecraft (web shells), indicating human-operated intrusion rather than purely automated scanning.
  • Any internet-exposed AhsayCBS instance running a vulnerable build should be treated as potentially already compromised and handled with an IR mindset: patch and hunt, not patch and hope.

Detection & Response

The detections below target the observable behaviors in this campaign: the AhsayCBS Java process spawning unexpected child processes (web shell execution and payload staging), the miner masquerading as Microsoft Edge, and the mining-pool network behavior XMRig cannot hide.

Sigma Rules

YAML
---
title: AhsayCBS Java Process Spawning Shell or Script Interpreter
id: 3f8a1c94-2b6d-4e51-9a72-c4d5e6f70819
status: experimental
description: Detects the AhsayCBS backup server Java process spawning command shells, script interpreters, or download utilities, consistent with web shell execution following exploitation of CVE-2026-105133.
references:
  - https://thehackernews.com/2026/10/attackers-exploit-ahsaycbs-flaws-to.html
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/10/21
tags:
  - attack.persistence
  - attack.t1505.003
  - attack.t1190
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith: '\java.exe'
    ParentCommandLine|contains: 'ahsay'
  selection_child:
    Image|endswith:
      - '\cmd.exe'
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\wscript.exe'
      - '\cscript.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
      - '\curl.exe'
  condition: selection_parent and selection_child
falsepositives:
  - Rare; legitimate AhsayCBS administrative scripts should be validated and excluded by full path
level: high
---
title: XMRig Miner Masquerading as Microsoft Edge
id: 91c2d7e0-4a5b-48f3-b6d1-8e9f0a1b2c3d
status: experimental
description: Detects execution of a Microsoft Edge-named binary from a non-standard path or with XMRig-style command-line arguments, matching the miner masquerading tradecraft seen in the AhsayCBS exploitation campaign.
references:
  - https://thehackernews.com/2026/10/attackers-exploit-ahsaycbs-flaws-to.html
  - https://attack.mitre.org/techniques/T1036/
  - https://attack.mitre.org/techniques/T1496/
author: Security Arsenal
date: 2026/10/21
tags:
  - attack.defense_evasion
  - attack.t1036
  - attack.impact
  - attack.t1496
logsource:
  category: process_creation
  product: windows
detection:
  selection_name:
    Image|endswith:
      - '\msedge.exe'
      - '\MicrosoftEdge.exe'
      - '\msedgewebview2.exe'
  filter_legit_path:
    Image|startswith:
      - 'C:\Program Files (x86)\Microsoft\Edge\'
      - 'C:\Program Files\Microsoft\Edge\'
      - 'C:\Windows\SystemApps\'
  selection_args:
    CommandLine|contains:
      - 'stratum+tcp'
      - 'stratum+ssl'
      - '--donate-level'
      - '--coin='
      - '-o pool.'
      - '--tls'
      - '--cpu-priority'
  condition: (selection_name and not filter_legit_path) or (selection_name and selection_args)
falsepositives:
  - User-installed Edge variants in non-default directories (validate signer and hash before tuning)
level: critical
---
title: Web Shell File Written to AhsayCBS Web Application Directory
id: b47e5f21-6c8a-4d92-a1e3-5f7b9c0d2e4f
status: experimental
description: Detects creation of JSP, JSPX, or script files within AhsayCBS web application directories, consistent with web shell deployment following CVE-2026-105133 authentication bypass.
references:
  - https://thehackernews.com/2026/10/attackers-exploit-ahsaycbs-flaws-to.html
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/10/21
tags:
  - attack.persistence
  - attack.t1505.003
logsource:
  category: file_event
  product: windows
detection:
  selection_path:
    TargetFilename|contains:
      - '\AhsayCBS\webapps\'
      - '\AhsayCBS\webapp\'
      - '\AhsayCBS\apache-tomcat\webapps\'
  selection_ext:
    TargetFilename|endswith:
      - '.jsp'
      - '.jspx'
      - '.war'
  condition: selection_path and selection_ext
falsepositives:
  - Legitimate Ahsay product updates (correlate with vendor update windows and signed installers)
level: high

KQL (Microsoft Sentinel / Defender)

The following hunt looks for the miner masquerade and mining-pool egress across both endpoint and network telemetry. Run it over at least the last 30 days on any estate with AhsayCBS deployed, and pivot on any hits to the originating parent process to determine whether the AhsayCBS service was the entry point.

KQL — Microsoft Sentinel / Defender
// Hunt 1: Edge-named binaries running outside legitimate paths, or with XMRig arguments
let legitEdgePaths = dynamic([@"C:\Program Files (x86)\Microsoft\Edge\", @"C:\Program Files\Microsoft\Edge\", @"C:\Windows\SystemApps\"]);
DeviceProcessEvents
| where Timestamp > ago(30d)
| where FileName in~ ("msedge.exe", "MicrosoftEdge.exe", "msedgewebview2.exe")
| extend IsLegitPath = FolderPath has_any (legitEdgePaths)
| extend MinerArgs = ProcessCommandLine has_any ("stratum+tcp", "stratum+ssl", "donate-level", "--coin=", "-o pool.")
| where IsLegitPath == false or MinerArgs == true
| project Timestamp, DeviceName, FileName, FolderPath, ProcessCommandLine, InitiatingProcessFileName, InitiatingProcessCommandLine, SHA256, AccountName
| order by Timestamp desc;

// Hunt 2: Outbound connections from Edge-named or unsigned binaries to common mining pool ports
DeviceNetworkEvents
| where Timestamp > ago(30d)
| where RemotePort in (3333, 4444, 5555, 7777, 8888, 9999, 14433, 45700)
| where InitiatingProcessFileName in~ ("msedge.exe", "MicrosoftEdge.exe", "xmrig.exe")
   or InitiatingProcessFolderPath has_any (@"\Temp\", @"\AppData\", @"\ProgramData\", @"\AhsayCBS\")
| summarize ConnectionCount = count(), RemoteIPs = make_set(RemoteIP, 10) by DeviceName, InitiatingProcessFileName, InitiatingProcessFolderPath, RemotePort
| order by ConnectionCount desc;

// Hunt 3: AhsayCBS Java service spawning shells or downloaders (web shell execution)
DeviceProcessEvents
| where Timestamp > ago(30d)
| where InitiatingProcessFileName =~ "java.exe"
  and InitiatingProcessCommandLine has "ahsay"
| where FileName in~ ("cmd.exe", "powershell.exe", "pwsh.exe", "certutil.exe", "bitsadmin.exe", "curl.exe", "wscript.exe", "cscript.exe")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, InitiatingProcessCommandLine, AccountName
| order by Timestamp desc;

For Linux-hosted AhsayCBS instances forwarding Syslog/CEF into Sentinel, hunt the Syslog table for java processes spawning /bin/sh or /bin/bash and for outbound connections to stratum ports.

Velociraptor VQL

Use this artifact for rapid triage of suspected AhsayCBS hosts — it enumerates masquerading processes and their network connections in a single collection:

VQL — Velociraptor
-- Hunt for Edge-masquerading miners and stratum connections on AhsayCBS hosts
LET proc = SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE (Name =~ '(?i)msedge|MicrosoftEdge'
   AND Exe !~ '(?i)Program Files.\\Microsoft\\Edge'
   AND Exe !~ '(?i)SystemApps')
   OR CommandLine =~ '(?i)stratum\+tcp|stratum\+ssl|donate-level|--coin=|xmrig'

SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime,
       netstat(Pid=Pid) AS Connections
FROM proc

Complement this with a glob() sweep for unauthorized web shells in the AhsayCBS Tomcat directories (e.g., glob(globs='C:\\Program Files\\AhsayCBS\\**\\webapps\\**\\*.jsp') adjusted to your install path) and check file timestamps against your last legitimate product update.

Triage and Remediation Script

Run the following on Windows-hosted AhsayCBS servers to verify version, enumerate suspicious Edge-named binaries outside legitimate paths, flag recent web content writes in the AhsayCBS tree, and check for stratum connections. Review output before taking destructive action — if you find artifacts, isolate the host and move to IR procedures rather than simply deleting files.

PowerShell
# AhsayCBS CVE-2026-105133 triage — run elevated on the backup server
$report = @{}

# 1) Locate AhsayCBS installation and capture version info for vendor comparison
$ahsayPaths = @("C:\Program Files\AhsayCBS", "C:\AhsayCBS", "D:\AhsayCBS")
$report.InstallPaths = $ahsayPaths | Where-Object { Test-Path $_ }
Write-Host "[+] AhsayCBS install paths found: $($report.InstallPaths -join ', ')"
Write-Host "[ACTION] Compare the installed build against the latest release at https://www.ahsay.com and upgrade immediately."

# 2) Hunt for Edge-named binaries outside legitimate locations
$edgeImpostors = Get-CimInstance Win32_Process |
  Where-Object { $_.Name -match '^(msedge|MicrosoftEdge|msedgewebview2)\.exe$' -and
                 $_.ExecutablePath -notmatch '^C:\\Program Files( \(x86\))?\\Microsoft\\Edge\\' -and
                 $_.ExecutablePath -notmatch '^C:\\Windows\\SystemApps\\' } |
  Select-Object ProcessId, Name, ExecutablePath, CommandLine
if ($edgeImpostors) { Write-Host "[!] SUSPICIOUS Edge-named processes found:"; $edgeImpostors | Format-List }

# 3) Check for XMRig-style command lines on any process
$minerArgs = Get-CimInstance Win32_Process |
  Where-Object { $_.CommandLine -match 'stratum\+tcp|stratum\+ssl|donate-level|--coin=|-o pool\.' } |
  Select-Object ProcessId, Name, ExecutablePath, CommandLine
if ($minerArgs) { Write-Host "[!] SUSPICIOUS mining arguments found:"; $minerArgs | Format-List }

# 4) Enumerate recent JSP/script writes in AhsayCBS web directories (web shell check)
foreach ($p in $report.InstallPaths) {
  Get-ChildItem -Path $p -Recurse -Include *.jsp,*.jspx,*.war -ErrorAction SilentlyContinue |
    Where-Object { $_.LastWriteTime -gt (Get-Date).AddDays(-60) } |
    Select-Object FullName, LastWriteTime, CreationTime
}

# 5) Check active connections to common stratum/mining ports
Get-NetTCPConnection -State Established -ErrorAction SilentlyContinue |
  Where-Object { $_.RemotePort -in 3333,4444,5555,7777,8888,9999,14433,45700 } |
  Select-Object LocalAddress, LocalPort, RemoteAddress, RemotePort, OwningProcess,
    @{n='ProcessName';e={(Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue).Name}}

Write-Host "[+] Triage complete. If any [!] findings exist: isolate the host, preserve volatile evidence, rotate ALL credentials stored in or managed by AhsayCBS, and begin IR scoping."

For Linux-hosted AhsayCBS instances:

Bash / Shell
# Check for Edge-masquerading or XMRig processes and stratum connections
ps auxww | grep -Ei 'xmrig|stratum\+|donate-level|msedge' | grep -v grep
ss -tulpn | grep -E ':(3333|4444|5555|7777|8888|9999|14433|45700)'

# Find recently modified web content in the AhsayCBS Tomcat/webapps tree (adjust install path)
find /usr/local/AhsayCBS -name '*.jsp' -o -name '*.war' 2>/dev/null | xargs ls -lt 2>/dev/null | head -40

# Review AhsayCBS service children for unexpected shells
pstree -ap $(pgrep -f ahsay | head -1)

Remediation

  1. Patch immediately. Upgrade AhsayCBS to the latest release from Ahsay that addresses CVE-2026-105133 and the companion flaw used in this campaign. Obtain the fixed build directly from the official vendor site at https://www.ahsay.com and validate installer integrity before deployment. Do not rely on the CVSS v4 5.5 score to deprioritize this — active, confirmed in-the-wild exploitation overrides the numeric severity.

  2. Remove network exposure. AhsayCBS management consoles should never be directly internet-reachable. Place the console behind a VPN or zero-trust access gateway, restrict the management ports to administrator source IPs via host and perimeter firewall rules, and disable the listener entirely if remote management is not required.

  3. Assume compromise on exposed instances. For any AhsayCBS server that was internet-reachable while running a vulnerable build: hunt with the queries above, inspect webapp directories for unauthorized JSP/WAR files, review service-account logins, and check persistence mechanisms (scheduled tasks, services, run keys, cron). A vulnerable backup server is also a credential store — rotate every credential AhsayCBS holds (backup destination credentials, API tokens, service accounts, admin passwords) even if you find no artifacts.

  4. Eradicate miner and web shells properly. Simply killing the miner process is insufficient. Remove the masquerading binary, the web shell, and any persistence the actors established; then rebuild the server from known-good media if interactive intrusion is confirmed. Given that this host manages your backups, verify backup job integrity and confirm backup repositories were not tampered with or encrypted — backup servers are a staging ground for ransomware detonation.

  5. Harden detections going forward. Deploy the Sigma rules and KQL hunts above to production. Alert on any Edge-signed-name binary executing from non-Microsoft paths, any child processes of the AhsayCBS Java service, and any egress to mining-pool ports. Consider egress filtering on the backup VLAN — backup servers have almost no legitimate need to initiate arbitrary outbound connections.

  6. Verify backups independently. Because the compromised asset is the backup platform itself, validate restorability of critical backups from an isolated copy before you need them.

If your team lacks the cycles to run this hunt across a distributed AhsayCBS fleet, this is exactly the class of threat where managed detection and rapid triage pays for itself: the difference between a cryptominer and a ransomware precursor on your backup server is usually about 48 hours.

Related Resources

Security Arsenal Alert Triage Automation AlertMonitor Platform Book a SOC Assessment platform Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.