Nezha Tool Used in New Cyber Campaign Targeting Web Applications
ID: fd959bc4-f56e-5d2b-91a9-b04f2423a93b
STIX ID: report--fd959bc4-f56e-5d2b-91a9-b04f2423a93b
Feed Name: Infosecurity Magazine (News)
Huntress discovered an August 2025 campaign where attackers gained access through an internet-exposed phpMyAdmin, used MariaDB general query log poisoning to plant a PHP web shell, then leveraged AntSword to deploy a Nezha agent (live.exe) and a Ghost RAT variant (x.exe), affecting over 100 systems across APAC and other regions; the operators disabled Windows Defender, created persistence named "SQLlite", and connected to China-linked C2 domains. Researchers recommend patching public-facing apps, enforcing authentication, and improving detection of web shells and post-exploitation activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
