AhsayCBS XMRig and web shell post-exploitation activity
Malware Activity
Summary
Hide ▲
Show ▼
Post-exploitation activity on compromised AhsayCBS hosts is dropping web shells and XMRig miners, extending attacker control and adding cryptomining after initial access. The miners are being disguised as Microsoft Edge to reduce detection, and the activity includes reconnaissance on impacted systems. The behavior followed exploitation of the AhsayCBS flaws and reflects a shift from access to sustained malicious use.
Related Happenings
AhsayCBS backup utility active exploitation wave (CVE-2026-105133, CVE-2026-105134)
Exploitation Wave
H score51
First: 09.10.2026 15:47
Last: 09.10.2026 15:47
Sources 1
How related:
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners.
About this happening:
Active exploitation of CVE-2026-105133 and CVE-2026-105134 in AhsayCBS backup utility is enabling remote code execution and post-compromise deployment of web she...
AhsayCBS backup utility active exploitation wave (CVE-2026-105133, CVE-2026-105134)
Exploitation WaveHow related: Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners.
About this happening: Active exploitation of CVE-2026-105133 and CVE-2026-105134 in AhsayCBS backup utility is enabling remote code execution and post-compromise deployment of web she...
AhsayCBS backup utility actively exploited authentication bypass and command injection flaws (multiple vulnerabilities)
Vulnerability
H score49
First: 09.10.2026 15:47
Last: 09.10.2026 15:47
Sources 1
How related:
CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java" component.
CVE-2026-105134 (CVSS v4 score: 9.3) - An operating system command injection vulnerability in the Replication Receiver component.
About this happening:
CVE-2026-105133 and CVE-2026-105134 in AhsayCBS are being actively exploited, enabling attackers to bypass authentication and run arbitrary commands on exposed systems...
AhsayCBS backup utility actively exploited authentication bypass and command injection flaws (multiple vulnerabilities)
VulnerabilityHow related: CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java" component. CVE-2026-105134 (CVSS v4 score: 9.3) - An operating system command injection vulnerability in the Replication Receiver component.
About this happening: CVE-2026-105133 and CVE-2026-105134 in AhsayCBS are being actively exploited, enabling attackers to bypass authentication and run arbitrary commands on exposed systems...
Steam discussion forums ClickFix campaign deploying XMRig miners
Campaign
H score34
First: 26.07.2026 01:37
Last: 26.07.2026 01:37
Sources 1
About this happening:
An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses he...
Steam discussion forums ClickFix campaign deploying XMRig miners
CampaignAbout this happening: An ongoing ClickFix campaign on Steam discussion forums is tricking users into running PowerShell commands that install XMRig cryptominers. The operation abuses he...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware Activity
H score23
First: 24.06.2026 23:58
Last: 24.06.2026 23:58
Sources 1
About this happening:
The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Edgecution malicious Microsoft Edge extension backdoor activity
Malware ActivityAbout this happening: The Edgecution malware is extending a Microsoft Edge browser foothold into host-level compromise by abusing Chrome Native Messaging and launching a Python-based back...
Sapphire Sleet Mastra npm supply-chain campaign
Campaign
H score42
First: 20.06.2026 17:09
Last: 20.06.2026 17:09
Sources 1
About this happening:
The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...
Sapphire Sleet Mastra npm supply-chain campaign
CampaignAbout this happening: The Mastra AI supply-chain campaign was attributed to Sapphire Sleet / BlueNoroff after Microsoft said the operation compromised the npm maintainer account "ehindero...
Timeline
-
09.10.2026 15:47 2 articles · 4h ago
AhsayCBS XMRig and web shell post-exploitation activity
Initial DisclosureAfter gaining access to AhsayCBS systems, operators began dropping web shells and XMRig miners to maintain control and monetize the compromise. The tooling was crafted to look benign, including use of the Microsoft Edge name.
Show sources
- Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge — thehackernews.com — 09.10.2026 15:47
- Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge — thehackernews.com — 09.10.2026 15:47