Hackers Abuse Popular Monitoring Tool Nezha as a Stealth Trojan
ID: 367cd7c6-e292-5594-b72b-a657fc6775b1
STIX ID: report--367cd7c6-e292-5594-b72b-a657fc6775b1
Feed Name: HackRead
Threat Score
**Executive summary:** Researchers report that the open-source server monitoring tool Nezha is being repurposed by attackers as a full-featured Remote Access Trojan (RAT) with SYSTEM/root-level capabilities, cross-platform support, low antivirus detection, and command-and-control infrastructure linked to Alibaba Cloud; organisations should proactively hunt for unapproved Nezha agents and focus on usage/context rather than treating tools as strictly benign or malicious.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
