Hackers Are Quietly Turning Backup Servers Into Crypto Mining Machines

·
Listen to this article~4 min

Attackers are exploiting unpatched AhsayCBS flaws to deploy webshells and crypto miners. Here's what you need to know—and how to protect your backup server.

### The Backup Server You Forgot About Is Now a Crypto Mine Imagine this: your backup management platform—the one thing you rely on to keep your data safe—is quietly being used to mine cryptocurrency and host hidden backdoors. That's exactly what's happening with AhsayCBS, a popular backup solution that has two unpatched security holes. One is critical, the other medium-severity. And attackers are already exploiting them in the wild. So if you're running AhsayCBS, this isn't a "someday" problem. It's a right-now problem. ### What Exactly Are They Doing? Once attackers slip through those unpatched flaws, they don't just snoop around. They drop webshells—tiny scripts that give them remote control over your server—and then install cryptocurrency miners. Your server starts burning CPU cycles to make them money. You might notice slower performance, higher electric bills, or weird network traffic. But often, you won't notice anything at all until it's too late. Here's the kicker: these vulnerabilities haven't been fixed yet. No patch. No official fix. That means every AhsayCBS instance out there is potentially a sitting duck. ### Why This Matters More Than You Think Backup servers are juicy targets. They hold copies of everything—customer data, financial records, intellectual property. If an attacker controls your backup server, they can encrypt or steal your backups, then demand a ransom. Or they can use your server as a launchpad to pivot deeper into your network. And crypto mining? That's just the cherry on top. It's a low-effort, high-reward scheme for attackers because they don't need to steal data—they just need your CPU. Plus, mining malware often comes with backdoors that let them come back later. > "The scariest part isn't the mining. It's the webshell. Once that's in place, the attacker can do anything—and they'll likely stay quiet to keep the free compute coming." ### What Should You Do Right Now? If you're using AhsayCBS, don't wait for a patch. Take action today: - **Isolate the server.** Put it behind a firewall and restrict access to only trusted IPs. - **Check for webshells.** Look for suspicious files in web-accessible directories. Common names include `shell.php`, `cmd.jsp`, or random strings. - **Monitor CPU usage.** A sudden spike could mean a miner is running. - **Consider alternatives.** If AhsayCBS can't be secured, migrate to a backup solution with a better security track record. - **Apply virtual patching.** If you have a WAF or IPS, create rules to block known exploit patterns. ### The Bigger Picture This isn't just about AhsayCBS. It's a reminder that backup software is often overlooked when it comes to security. We patch our operating systems, our browsers, our web apps—but backup tools? They sit in the corner, quietly doing their job, until they become a liability. Attackers know this. They target the forgotten corners of your infrastructure. So the next time you review your security posture, don't skip the backup server. It might be the weakest link. And if you're not sure whether you're affected? Assume you are until proven otherwise. Run a scan, check logs, and talk to your security team. Because the cost of ignoring this—data loss, downtime, ransom demands—is far higher than the cost of a few hours of investigation. Stay safe out there. And maybe check your CPU usage right now.