logo

Hackers Abuse Popular Monitoring Tool Nezha as a Stealth Trojan

ID: 367cd7c6-e292-5594-b72b-a657fc6775b1

STIX ID: report--367cd7c6-e292-5594-b72b-a657fc6775b1

Feed Name: HackRead

Threat Score
72/100

Date Published: 2025-12-22

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

**Executive summary:** Researchers report that the open-source server monitoring tool Nezha is being repurposed by attackers as a full-featured Remote Access Trojan (RAT) with SYSTEM/root-level capabilities, cross-platform support, low antivirus detection, and command-and-control infrastructure linked to Alibaba Cloud; organisations should proactively hunt for unapproved Nezha agents and focus on usage/context rather than treating tools as strictly benign or malicious.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.