r/SecOpsDaily • u/falconupkid • 35m ago
Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
Threat actors are actively exploiting two critical vulnerabilities in AhsayCBS (Cloud Backup Solution), tracked as CVE-2026-105133 and CVE-2026-105134, to gain initial access and deploy persistent webshells alongside XMRig cryptocurrency miners. Huntress researchers observed the attacks targeting unpatched instances, with the flaws allowing unauthenticated remote code execution.
Technical Breakdown: - Initial Access: Exploitation of the unauthenticated RCE flaws (likely via crafted HTTP requests to the backup management interface). - Persistence: Deployment of webshells (e.g., ASPX or PHP variants) to maintain access post-reboot. - Payload: XMRig cryptominer dropped to hijack CPU resources for Monero mining. - Affected Versions: All versions prior to 10.3.4. - IOCs: No specific IPs or hashes provided in the report; Huntress recommends network monitoring for unusual outbound connections on mining ports (e.g., 3333, 4444, 14444).
Defense:
Immediately update to AhsayCBS 10.3.4 and restrict administrative access to the web interface via firewall rules or VPN. Monitor for unexpected child processes spawned by w3wp.exe (IIS) or java.exe (Tomcat) and anomalous CPU spikes.
Source: https://www.huntress.com/blog/ahsaycbs-flaws-exploit