logo

Monitoring Tool Nezha Abused For Stealthy Post-Exploitation Access

ID: a990d384-520a-5252-85bb-796d4b828a98

STIX ID: report--a990d384-520a-5252-85bb-796d4b828a98

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2025-12-22

Date Updated: 2026-04-22

...
...

Ontinue researchers reported a campaign in which attackers abused the legitimate Nezha monitoring platform as a post-exploitation RAT: silently installed agents run as SYSTEM/root to provide interactive shells, file transfers and remote command execution, register no detections on VirusTotal, and a compromised dashboard suggested hundreds of connected endpoints, making detection and attribution difficult.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.