Attackers Exploit AhsayCBS Flaws to Install XMRig Miners Disguised as Microsoft Edge

Summary
Attackers are exploiting two AhsayCBS flaws to gain remote code execution and deploy web shells and XMRig miners. Huntress says version 10.3.4 may also be affected and recommends restricting management-interface access.
Key points
- Attackers began exploiting two AhsayCBS flaws on October 7, chaining them to bypass authentication and execute commands remotely.
- Huntress estimated that five organizations had been affected as of October 8, 2026.
- Post-exploitation activity includes reconnaissance, web shells, and XMRig miners disguised as Microsoft Edge using the filename edge.exe.
- A PowerShell script launches mining and uses anti-analysis checks that stop mining when Windows Task Manager is opened.
- In at least one incident, attackers downloaded a vulnerable driver, possibly to gain kernel-level access and optimize mining.
- Although NVD advisories listed version 10.3.4 as fixed, Huntress reported that it is also affected.
- Huntress recommends limiting AhsayCBS management-interface access to trusted IP addresses or requiring VPN access.
Article Details
- Vulnerability Types
- Authentication bypass
- Remote code execution
- Affected Versions
- 10.3.4
- Exploitation Status
- active
- Exploit Availability
- unknown
- Patch Status
- unavailable
- Workarounds
- Restrict access to the AhsayCBS management interface to trusted IP addresses or require VPN access.
MITRE ATT&CK
T1036 · MasqueradingThe XMRig miners used the filename edge.exe to masquerade as Microsoft Edge.T1059.001 · PowerShellA PowerShell script, Taskgmr.ps1, facilitated cryptomining and monitored Windows Task Manager.T1105 · Ingress Tool TransferIn at least one incident, certutil.exe was used to download WinRing0x64.sys to the TEMP folder.T1190 · Exploit Public-Facing ApplicationThreat actors exploited AhsayCBS flaws in the externally accessible web application to gain remote code execution.T1496 · Resource HijackingThreat actors deployed XMRig cryptocurrency miners on compromised hosts.T1505.003 · Web ShellThreat actors dropped web shells on compromised hosts.
Malware
Products
AhsayCBSThreat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners.Microsoft Edgeare conducting reconnaissance, dropping web shells, planting XMRig cryptominers masquerading as Microsoft Edge, and more," the cybersecurity company said. "They also dropped what appears to be an AI-assistedMicrosoft Windowscompany said. "They also dropped what appears to be an AI-assisted PowerShell script that monitors the Windows Task Manager and shuts it down if it remains open for too long in the middle of the night."
Tools
certutilIn at least one incident, the threat actors are said to have used the built-in "certutil.exe" binary to download a legitimate-but-vulnerable driver ("WinRing0x64.sys") to the TEMP folder, likely with the aim of gainingcurlis a PowerShell script ("Taskgmr.ps1") that facilitates cryptomining operations after it's launched via curl.PowerShellEdge, and more," the cybersecurity company said. "They also dropped what appears to be an AI-assisted PowerShell script that monitors the Windows Task Manager and shuts it down if it remains open for too long in the