Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan
ID: 356ee07d-7e76-533d-83dc-45ea38573ee5
STIX ID: report--356ee07d-7e76-533d-83dc-45ea38573ee5
Feed Name: cybersecurityNews.com
Researchers at Ontinue uncovered a campaign where threat actors repurposed the legitimate Nezha monitoring tool as a remote access trojan, deploying agents that run with SYSTEM/root privileges and connecting to attacker-controlled C2 infrastructure (notably IP 47.79.42.91 on Alibaba Cloud). Deployment scripts revealed authentication tokens and disabled TLS, the legitimate binary evaded detection on VirusTotal, and hundreds of endpoints were compromised, prompting recommendations for hunting Nezha presence and behavioral monitoring for suspicious terminal and file activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
