A sophisticated cyberattack campaign, active since August 2025, involves a threat actor from Chinaabusing the legitimate Nezha tool to execute commands and deploy malware on compromised web servers.

This campaign, uncovered by Huntress, represents the first public report of Nezha being abused in this manner, highlighting a shift toward leveraging open source tools to evade detection.
The attackers used a creative log poisoning technique to gain initial access before deploying the infamous Ghost RAT, primarily targeting entities in Taiwan, Japan, South Korea, and Hong Kong.
See also: Crimson Collective exports data via AWS services
Nezha Abuse: How does the attack work?
The attack began by exploiting a vulnerable, publicly accessible phpMyAdmin that lacked proper authentication. After gaining access from an AWS-hosted IP in Hong Kong, the attackers immediately set the interface language to Simplified Chinese.
They then used an ingenious technique known as log poisoning to install a web shell. By tampering with MariaDB's logging functions, the threat actor set the general log file to a PHP file within the webroot.

It then executed an SQL query containing a one-liner PHP web shell, effectively writing their backdoor to the executable log file. This method allowed the attackers to execute arbitrary code on the server using tools like AntSword, which are designed to handle such backdoors.
After gaining control with the web shell, the hackers' main goal was to develop a more persistent and flexible tool. They used the AntSword connection to download and execute live.exe, an installer for a Nezha agent.
See also: Hackers breach databases with legal commands
Nezha is a legitimate, open-source tool for server monitoring and task management. However, in this case, it was used as a malicious implant.
The agent configuration file pointed to the command and control (C2) server, which operated a Nezha control panel. This panel revealed that the attackers had compromised over 100 victim machines in 53 regions, with a significant concentration in East Asia (attacks aligned with China's geopolitical interests).
With the Nezha agent providing persistent and silent access, the attackers escalated their privileges. They used command execution capabilities to launch an interactive PowerShell session, where they created an exception rule in Windows Defender to avoid detection.
See also: New invisible FUD Android RAT hosted on GitHub

Shortly after, they deployed x.exe, a variant of the infamous Ghost RAT. Analysis of this malware revealed communication protocols and persistence mechanisms consistent with previous campaigns attributed to Chinese APT groups. The incident highlights the need to strengthen publicly accessible applications and monitor for abuse of legitimate softwareas threat actors continue to adapt their designs to stay ahead of network defenders.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
