Skip to content

Image: cdn.builder.io · rights & removal

Executive Summary

Threat actors are exploiting two chained vulnerabilities in AhsayCBS to gain remote code execution. The first vulnerability, CVE-2026-105133, allows for authentication bypass via the checkSysPwd function. This is then chained with CVE-2026-105134, a critical vulnerability in Replication Receiver, which permits unauthenticated remote code execution as NT AUTHORITY/SYSTEM on the host by allowing an authentication bypass that substitutes valid credentials.
Following exploitation, threat actors observed deploying JSP webshells and using the compromised service to execute commands. Post-exploitation activity included dropping files from external cloud storage, such as Taskgmr.ps1, msedge.exe, edge.exe, and config.json into temporary directories. Furthermore, miners were deployed using XMRig, which masqueraded as legitimate processes like msedge.exe by leveraging NSSM for persistence. The attack also involved loading a vulnerable kernel driver, WinRing0x64.sys, to facilitate low-level access for the cryptomining operation.
The resulting chain demonstrates a path from initial access via API flaws to achieving full system compromise, establishing persistence through modified services, and executing resource-intensive activities like cryptocurrency mining with kernel privileges. Organizations are advised to restrict management interface access until patches are available.

Facts Only

* CVE-2026-105133 affects the checkSysPwd function in filecom/ahsay/obs/api/ApiStructsAction.java and can lead to improper authentication.
* CVE-2026-105134 affects /rps/api/json/UpdateReceivers.do of Replication Receiver in AhsayCBS, allowing for unauthenticated remote code execution as NT AUTHORITY/SYSTEM on the host via an authentication bypass.
* Threat actors chained these vulnerabilities to gain access and execute code.
* Post-exploitation involved deploying .jsp webshells in the web application directory.
* Threat actors used cbssvcX64.exe to spawn commands, dropping files like Taskgmr.ps1, msedge.exe, edge.exe, and config.json from hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com into %TEMP% or ../AppData/Local/Temp.
* Cryptomining was executed using XMRig.
* XMRig (edge.exe) was dropped in Temp folders and established network connections on port 8029 to an XMR pool at 51.195.127[.]124:8029 and xmr.kryptex[.]network.
* PowerShell scripts, such as Taskgmr.ps1, were used, which included anti-analysis functions and checked for the presence of Task Manager to manage persistence.
* A malicious service, MicrosoftEdgeUpdateSvc, was created to persist activity by running msedge.exe from the Temp folder with SYSTEM privileges.
* msedge.exe was determined to be a modified copy of NSSM used to maintain the execution of edge.exe while masquerading as a legitimate service.
* Threat actors used certutil.exe to download WinRing0x64.sys from hxxp://imagefiles-backup.oss-ap-southeast-7.aliyuncs[.]com into the TEMP folder.

Full Take

The observed threat chain reveals a methodical progression designed not merely for initial access but for deep, stealthy system compromise and resource extraction. The core pattern involves exploiting sequential flaws to transition from a web application vulnerability (authentication bypass) to remote code execution, which then facilitates a multi-stage persistence mechanism. This sequence moves logically from external interaction to internal control.
The subsequent post-exploitation steps are highly sophisticated, focusing on evasion and covert operation rather than immediate destruction. The use of fileless persistence via NSSM manipulation disguising the miner activity as legitimate system services, combined with the execution of PowerShell scripts specifically designed to evade analysis by monitoring running processes like Task Manager, points toward an actor that prioritizes long-term presence over quick exfiltration. This indicates a pattern where attackers leverage legitimate operating system tools and software features—like kernel drivers and service management utilities—to blend malicious activity into normal system operations.
The integration of the cryptominer with kernel-level access via WinRing0x64.sys suggests a deliberate escalation to maximize performance and minimize detection, indicating an understanding that standard endpoint security often fails at the deepest levels. The distribution of artifacts from cloud storage and the use of custom scripts for internal orchestration highlight a pattern where initial exploitation is just the opening salvo in a larger campaign focused on establishing deep, persistent, and covert control over compromised infrastructure.
BRIDGE QUESTIONS:
What are the specific trust boundaries within AhsayCBS that allowed an externally triggered vulnerability to directly result in arbitrary kernel driver loading?
How does the dependency on external hosting for payload delivery fundamentally change the risk assessment when assessing the integrity of managed backup systems?
If defenders focus solely on patching the initial CVEs, what systemic gaps remain regarding the persistence and resource utilization observed after the exploitation occurred?

From the original · Huntress Labs

Acknowledgements: Special thanks to Dipo Rodipe, John Hammond, Susannah Matt, Ben Nahorney, and Lindsey Welch for their contributions to this investigation and writeup. Update 10/8/26 @ 6pm ET After further investigation, Huntress has determined that Ahsay 10.3.4 is also affected by these vulnerabilities.
Read the full story at huntress.com

Sentinel — Human

Confidence

This text reads like a forensic report or threat intelligence briefing derived from an actual investigation, characterized by highly specific technical detail and structured analysis.

Signals Detected
low severity: Sentence length variance and flow suggests human narrative structure, despite technical density.
low severity: The text flows logically from vulnerability discovery to post-exploitation behavior to mitigation guidance. The tone is authoritative but grounded in specific findings.
low severity: The structure—especially the transition from theoretical vulnerabilities to highly detailed, named post-exploitation steps (webshells, miners, persistence)—suggests coordinated, expert reporting rather than raw generation.
low severity: The inclusion of specific CVE numbers, file paths, known threat actor TTPs, and detailed IOC structure points toward grounded, verifiable investigative work.
Human Indicators
Specific attribution to a named group ('Huntress') and the establishment of specific artifacts (CVEs, custom Sigma Rules, file paths) suggests proprietary investigation.
The incorporation of detailed, non-obvious technical linkage between disparate activities (e.g., using WinRing0 driver for mining alongside RCE) exhibits deep contextual knowledge typical of security research.
Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer | Huntaegis