Hackers Abuse AhsayCBS Flaws to Run XMRig Mines Masked as Edge

Attackers have recently exploited two security vulnerabilities in the AhsayCBS backup application to take over systems, plant web shells, and unleash XMRig cryptocurrency miners disguised as Microsoft Edge. The flaws—CVE-2026-105133 and CVE-2026-105134—allow intruders to bypass authentication and execute arbitrary commands on affected machines. Telecom and IT environments relying on AhsayCBS should treat this as an urgent threat.

The Weak Points & Attack Timeline

The first vulnerability, CVE-2026-105133 (CVSS v4 score: 5.5), is an improper authentication flaw in the checkSysPwd() function inside the component com/ahsay/obs/api/ApiStructsAction.java. The second, CVE-2026-105134 (CVSS v4 score: 9.3), is an OS command injection issue located in AhsayCBS’s Replication Receiver module. By chaining these two, adversaries accomplish full remote code execution without valid credentials. These CVEs were officially released on October 4, 2026.

Exploit attempts were first spotted on October 7, 2026, at 11:20 p.m. UTC, with attackers actively abusing these flaws to gain remote access. By October 8, around five organizations have already been compromised. Post-breach activity includes reconnaissance, web shell implantation, and deploying stealthy crypto-miners.

Sandboxing Crypto-Mining & Evasion Techniques

The malicious miner binaries are cloaked under the name “edge.exe” so they are mistaken for Microsoft Edge. Additionally, attackers deploy a PowerShell script named Taskgmr.ps1 via curl. A notable twist: the script appears to be architected with help from an AI assistance tool.

This script includes anti-analysis features—if a user opens Task Manager, the mining ceases. If Task Manager is left open overnight past 6 p.m. for more than an hour, it gets terminated. Attackers also utilized certutil.exe to download a vulnerable driver (WinRing0x64.sys) into the TEMP folder to gain kernel-level access and boost mining efficiency.

Patch Status & Mitigation Advice

The software version that includes the fix is 10.3.4, but reports suggest even systems already on that version are being impacted—indicating continuing zero-day risk. In response, security firms strongly recommend restricting access to the AhsayCBS management interface. Ideally, that means limiting access to trusted IPs or only via VPN.

Why This Matters

This incident highlights several worrying trends in enterprise cybersecurity: threat actors combining multiple vulnerabilities to evade defenses; using AI-assisted scripting to adapt tactics; and mining operations disguised as trusted apps to fly under admin radar. Backup solutions like AhsayCBS are often exposed externally, which multiplies risk.

For defenders: monitor for unfamiliar “edge.exe” processes, unexpected PowerShell scripts like Taskgmr.ps1, and the presence of WinRing0x64.sys. If the management UI is externally reachable, consider isolating it behind a firewall or VPN. As patching may not yet fully mitigate risk, active hunt for compromise indicators is critical.

Bold attackers exploiting flaws in backup platforms could signal a rising preference for cryptojacking over data theft. Watch for similar blends of privilege bypass, command injection, and deception in identity of legitimate apps. How well organizations adapt patching, access controls, and detection will determine whether this becomes a widespread tool for criminal monetization.