What exactly is happening with AhsayCBS?
Threat actors are actively exploiting an unauthenticated file upload vulnerability in the AhsayCBS backup software. This flaw allows them to upload malicious webshells to the server
Has our backup data been stolen, encrypted, or deleted?
Based on current telemetry, the threat actor's sole objective is resource hijacking for cryptomining.
We have not observed data exfiltration, ransomware deployment, or backup deletion in this campaign. However, because the attackers achieve SYSTEM-level privileges, data compromise cannot be entirely ruled out.
Why are you recommending a full host re-image instead of just deleting the malicious files?
The attackers have been observed to establish SYSTEM-level persistence as a fake Windows Service. When a threat actor achieves kernel-level and SYSTEM access, relying on simple file deletion is highly risky, as they can easily hide secondary backdoors. Re-imaging is the only way to guarantee the environment is secure.
Why do we need to perform a "clean install" of AhsayCBS instead of just running the software updater?
If the software is updated over a compromised installation, the updater may not remove the hidden .jsp webshells or malicious configurations the attacker left behind in the web application directories. A completely fresh installation ensures the application is free of lingering backdoors.
How will I know if any of my managed hosts are affected?
Huntress is actively hunting for this threat. If we detect malicious activity we will report
We do not know preemptively if versions/installed instances are exposed
What should we do right now to prevent this on uncompromised hosts?
Immediately update any AhsayCBS deployments to the latest patched version provided by the vendor.
Additionally, since this exploit targets the external-facing portion of the service, restrict web access to the Ahsay management interface to trusted IP addresses or require a VPN for access.