logo

Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan

ID: 356ee07d-7e76-533d-83dc-45ea38573ee5

STIX ID: report--356ee07d-7e76-533d-83dc-45ea38573ee5

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-12-23

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Researchers at Ontinue uncovered a campaign where threat actors repurposed the legitimate Nezha monitoring tool as a remote access trojan, deploying agents that run with SYSTEM/root privileges and connecting to attacker-controlled C2 infrastructure (notably IP 47.79.42.91 on Alibaba Cloud). Deployment scripts revealed authentication tokens and disabled TLS, the legitimate binary evaded detection on VirusTotal, and hundreds of endpoints were compromised, prompting recommendations for hunting Nezha presence and behavioral monitoring for suspicious terminal and file activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.