logo

The Crown Prince, Nezha: A New Tool Favored by China-Nexus Threat Actors

ID: 3d934e90-c829-5349-992a-bbb16603d460

STIX ID: report--3d934e90-c829-5349-992a-bbb16603d460

Feed Name: Huntress Blog

Threat Score
78/100

Date Published: 2025-10-15

Date Updated: 2026-04-28

...
...

**Executive summary:** Huntress discovered a multi-stage intrusion (Aug 2025) where attackers used phpMyAdmin log poisoning to drop a China Chopper web shell, used AntSword to run remote commands, installed a Nezha RMM agent, and deployed Ghost RAT across more than 100 victims primarily in Taiwan, Japan, South Korea and Hong Kong; the report provides detailed malware analysis, IOCs (files, domains, IPs, mutexes), victim geography, and TTPs and assesses a China-nexus actor (while noting a possible VPS-enthusiast motivation).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.