logo

China-Nexus Actors Weaponize 'Nezha' Open Source Tool

ID: a6e640ef-b202-5904-a2c9-bf29266ad1bf

STIX ID: report--a6e640ef-b202-5904-a2c9-bf29266ad1bf

Feed Name: Dark Reading

Threat Score
82/100

Date Published: 2025-10-08

Date Updated: 2026-05-05

Author: Nate Nelson, Contributing Writer

...
...

A China-linked threat actor has been exploiting exposed web administration panels (notably unauthenticated phpMyAdmin) and performing log-poisoning to install web shells, then using AntSword to deploy Nezha (an open-source RMM) and Gh0stRAT across a campaign that has affected over 100 organizations (primarily in Southeast Asia) to enable persistent remote control and disable defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.