Find notable cyber news and cases, enriched with sources, timelines, and signals.

Nezha post-exploitation remote access campaign

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

Attackers are abusing Nezha as a post-exploitation remote access tool, giving compromised hosts full command control and increasing the risk of persistence and lateral movement. The activity spans Windows and Linux environments and can expose SYSTEM/root-level access without requiring exploitation. Because the agent stays quiet until operators issue commands, signature-based detection is likely to miss it. A review of the linked dashboard suggested hundreds of endpoints could have been connected.

Related Happenings

Suspected China-linked Nezha-to-Gh0st RAT campaign

Campaign
H score37 First: 08.10.2025 16:56 Last: 08.10.2025 16:56 Sources 1

About this happening: A China-linked intrusion campaign abused Nezha to deliver Gh0st RAT, giving the operators remote control over more than 100 victim machines across multiple countri...

Nezha agent and Ghost RAT malware activity on compromised web servers

Malware Activity
H score25 First: 08.10.2025 16:00 Last: 08.10.2025 16:00 Sources 1

About this happening: Nezha and Ghost RAT were installed on compromised web servers, giving attackers remote monitoring, task execution, and persistence. The malware chain mattered because it a...

Timeline

  1. 22.12.2025 16:30 2 articles · 6mo ago

    Ontinue reports Nezha post-exploitation access

    Technical Analysis Update

    Ontinue’s Cyber Defense Center identified attackers abusing Nezha, a legitimate open-source server monitoring tool, as a post-exploitation remote access platform against compromised Windows and Linux systems. The agent can provide SYSTEM/root-level access by design without exploitation or privilege escalation, support command execution, file transfers, and interactive terminal sessions, and stay hidden until operators begin issuing commands; a review of the exposed dashboard suggested hundreds of endpoints may have been connected.

    Show sources