The Crown Prince, Nezha: A New Tool Favored by China-Nexus Threat Actors
ID: 3d934e90-c829-5349-992a-bbb16603d460
STIX ID: report--3d934e90-c829-5349-992a-bbb16603d460
Feed Name: Huntress Blog
**Executive summary:** Huntress discovered a multi-stage intrusion (Aug 2025) where attackers used phpMyAdmin log poisoning to drop a China Chopper web shell, used AntSword to run remote commands, installed a Nezha RMM agent, and deployed Ghost RAT across more than 100 victims primarily in Taiwan, Japan, South Korea and Hong Kong; the report provides detailed malware analysis, IOCs (files, domains, IPs, mutexes), victim geography, and TTPs and assesses a China-nexus actor (while noting a possible VPS-enthusiast motivation).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
