Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026

The Security Coverage Gap is a Math Problem

June 26, 2026

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Nezha Tool Used in New Cyber Campaign Targeting Web Applications
News

Nezha Tool Used in New Cyber Campaign Targeting Web Applications

Team-CWDBy Team-CWDOctober 8, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A newly uncovered cyber campaign featuring the open-source tool Nezha has been observed targeting vulnerable web applications.

Beginning in August 2025, Huntress analysts traced a sophisticated intrusion that used creative log poisoning techniques to implant a PHP web shell, later managed with AntSword and followed by the installation of both the Nezha agent and Ghost RAT malware.

The discovery marks the first public reporting of Nezha being used to facilitate web server compromises. The monitoring and task-management utility, typically employed for legitimate system administration, was repurposed by threat actors linked to China-based infrastructure. 

How the Attack Unfolded

Huntress investigators found that the attackers gained access through a phpMyAdmin panel exposed to the internet.

Using an AWS-hosted IP, they switched the interface language to Simplified Chinese before executing a series of SQL commands. These actions enabled the general query log in MariaDB and directed it to write to a .php file, effectively planting a hidden backdoor within normal log data.

The intruders then controlled the compromised web server using AntSword, downloading a file named “live.exe,” which turned out to be the Nezha agent. Once installed, this agent connected to a command server at c.mid[.]al, allowing remote monitoring and task execution.

“This incident highlights the requirement to ensure that public-facing applications are patched,” Huntress researchers said.

“By understanding the step-by-step process used by attackers like this, we can better tune our tools.”

Read more on web shells: Microsoft: Attackers Actively Compromising On-Prem SharePoint Customers

Huntress found that more than 100 victim systems were communicating with the attacker’s Nezha dashboard.

Most affected machines were located in Taiwan, Japan, South Korea and Hong Kong. Analysts also noted a small number of infections worldwide, including in the US, India and several European nations.

The attackers utilized Nezha to execute PowerShell commands that disabled Windows Defender scans before deploying “x.exe,” a variant of Ghost RAT.

The malware established persistence under the name “SQLlite” and communicated with command-and-control (C2) domains registered through China-linked entities.

Protective Measures

Huntress researchers recommended that organizations take several defensive measures to prevent similar intrusions.

These include:

  • Ensuring public-facing applications are patched and hardened

  • Making sure authentication is required wherever possible, including in test environments

  • Gaining visibility and detection logic to spot post-exploitation activity such as web shells, suspicious service creation and executables running from unusual directories

Defenders must remain alert as threat actors continue to blend legitimate software with malicious intent to evade detection.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleEvolving Enterprise Defense to Secure the Modern AI Supply Chain
Next Article New Android Trojan “Datzbro” Tricking Elderly with AI-Generated Facebook Travel Events
Team-CWD
  • Website

Related Posts

News

Apple Patches Beats Studio Buds Flaw Letting Nearby Attackers Spy via Microphone

June 26, 2026
News

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
News

How to Find Hidden Access Risks Inside Your Network

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

How the always-on generation can level up their cybersecurity game

September 11, 2025

How to tell if a voice call is AI or not

February 23, 2026

Is it OK to let your children post selfies online?

February 17, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.