Hackers Are Quietly Turning Backup Servers Into Crypto Miners
Michael Miller ·
Listen to this article~4 min
Threat actors are exploiting unpatched AhsayCBS flaws to deploy webshells and crypto miners. Learn how to protect your backup infrastructure before it's too late.
### When Your Backup Server Becomes the Hacker's Playground
Imagine coming into work Monday morning, coffee in hand, and finding your backup management console is now mining Monero for someone halfway around the world. That's not a hypothetical—it's happening right now to organizations running AhsayCBS. Two vulnerabilities, one critical and one medium-severity, remain unpatched, and threat actors are actively exploiting them to drop webshells and cryptominers on exposed systems.
AhsayCBS is a popular backup and restore platform used by managed service providers and enterprises to protect client data. It's the kind of software that sits quietly in the background, trusted to keep things safe. Which is exactly why attackers love it—nobody's watching the watcher.
### What Attackers Are Actually Doing
The playbook is familiar but effective. Once inside, attackers deploy a webshell—a tiny script that gives them persistent remote access through the web server. From there, they can move laterally, steal credentials, or just sit and wait.
But the real payload here is crypto mining. The attackers install a miner that quietly siphons CPU cycles to generate cryptocurrency. On a beefy backup server with plenty of processing power, that's a nice payday for them and a slow, painful performance drain for you.
- **Webshells** grant long-term access that survives reboots
- **Crypto miners** eat up CPU and drive up your power bill
- **Lateral movement** lets them pivot to other systems on your network
- **Data theft** is always on the table when backups are involved
### Why Unpatched Flaws Are a Goldmine
The critical flaw allows remote code execution—the holy grail for attackers. The medium-severity bug is likely used for privilege escalation or information disclosure. Together, they form a one-two punch that's hard to defend against if you haven't patched.
Here's the kicker: there's no official fix yet. The vendor hasn't released a patch, which means every exposed AhsayCBS instance is a sitting duck. Attackers know this, and they're scanning for vulnerable servers at scale.
> "The window between disclosure and exploitation is now measured in hours, not weeks. If you're running unpatched backup software, you're already behind."
### What You Can Do Right Now
No patch doesn't mean no options. You can still reduce your risk significantly with a few practical steps.
- **Isolate the server.** Put AhsayCBS behind a firewall and restrict access to trusted IPs only. If it doesn't need to face the internet, don't let it.
- **Monitor for webshells.** Look for unusual files in web-accessible directories. Tools like YARA rules can help.
- **Watch CPU usage.** A sudden spike in CPU or power consumption is a red flag for hidden miners.
- **Segment your network.** Don't let a compromised backup server become a launching pad for the rest of your infrastructure.
- **Consider alternatives.** If the vendor stays silent, it might be time to evaluate other backup solutions with a stronger security track record.
### The Bigger Picture
This isn't just about AhsayCBS. It's a reminder that backup infrastructure is a prime target. Attackers know that if they can compromise your backups, they can cripple your recovery. Ransomware gangs have been doing this for years—now crypto miners are getting in on the action.
The lesson? Treat your backup servers like the crown jewels. Patch what you can, isolate what you can't, and never assume you're too small to be a target. Because in the world of automated exploitation, everyone's a target.