Attackers Exploit AhsayCBS Flaws to Install XMRig Miners Disguised as Microsoft Edge

· Original article ↗

Summary

Attackers are exploiting two AhsayCBS flaws to gain remote code execution and deploy web shells and XMRig miners. Huntress says version 10.3.4 may also be affected and recommends restricting management-interface access.

Key points

  • Attackers began exploiting two AhsayCBS flaws on October 7, chaining them to bypass authentication and execute commands remotely.
  • Huntress estimated that five organizations had been affected as of October 8, 2026.
  • Post-exploitation activity includes reconnaissance, web shells, and XMRig miners disguised as Microsoft Edge using the filename edge.exe.
  • A PowerShell script launches mining and uses anti-analysis checks that stop mining when Windows Task Manager is opened.
  • In at least one incident, attackers downloaded a vulnerable driver, possibly to gain kernel-level access and optimize mining.
  • Although NVD advisories listed version 10.3.4 as fixed, Huntress reported that it is also affected.
  • Huntress recommends limiting AhsayCBS management-interface access to trusted IP addresses or requiring VPN access.

Article Details

Vulnerability Types
  • Authentication bypass
  • Remote code execution
Affected Versions
  • 10.3.4
Exploitation Status
active
Exploit Availability
unknown
Patch Status
unavailable
Workarounds
  • Restrict access to the AhsayCBS management interface to trusted IP addresses or require VPN access.

MITRE ATT&CK

Malware

Products

Tools

Related Articles