Monitoring Tool Nezha Abused For Stealthy Post-Exploitation Access
ID: a990d384-520a-5252-85bb-796d4b828a98
STIX ID: report--a990d384-520a-5252-85bb-796d4b828a98
Feed Name: Infosecurity Magazine (News)
Threat Score
Ontinue researchers reported a campaign in which attackers abused the legitimate Nezha monitoring platform as a post-exploitation RAT: silently installed agents run as SYSTEM/root to provide interactive shells, file transfers and remote command execution, register no detections on VirusTotal, and a compromised dashboard suggested hundreds of connected endpoints, making detection and attribution difficult.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
