08-10-2026
Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
https://www.huntress.com/blog/ahsaycbs-flaws-exploit
Report completeness: High
Threats:
Xmrig_miner
Nssm_tool
Xmr_miner
Victims:
Managed service providers, System integrators, Backup software sector
Geo:
Taiwan, Vietnam, United states, France, Hong kong
CVEs:
CVE-2026-105133 [Vulners]
CVSS V3.1: 7.3,
Vulners: Exploitation: Unknown
CVE-2026-105134 [Vulners]
CVSS V3.1: 10.0,
Vulners: Exploitation: Unknown
TTPs:
Tactics: 8
Technics: 16
IOCs:
File: 5
Url: 6
IP: 8
Domain: 3
Path: 1
Hash: 3
Email: 0
BrowserExtension: 0
Soft:
Microsoft Edge, curl, Windows service, Microsoft Edge Update, Alibaba Cloud, Microsoft 365
Crypto:
monero
Algorithms:
sha256
Functions:
Get-Date
Languages:
powershell, java
SIGMA: Found
Links:
https://github.com/huntresslabs/threat-intel/blob/main/2026/2026-10/AhsayCBS\_XMRig\_Miner/proc\_creation\_win\_susp\_ahsaycbs\_unexpected\_child\_process.ymlhave more...
https://github.com/huntresslabs/threat-intel/tree/main/2026/2026-10/AhsayCBS\_XMRig\_Minerhttps://github.com/huntresslabs/threat-intel/blob/main/2026/2026-10/AhsayCBS\_XMRig\_Miner/proc\_creation\_win\_susp\_fake\_edge\_daemonized\_miner.yml