Close Menu
TechurzTechurz
    What's Hot

    Silicon Valley loves young founders. Until it doesn’t.

    July 31, 2026

    AI labs want to pump the brakes, but Amazon and SpaceX are still blasting off

    July 31, 2026

    Smallest.ai raises $13M to build ultra-fast voice AI that sounds genuinely human

    July 31, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • Silicon Valley loves young founders. Until it doesn’t.
    • AI labs want to pump the brakes, but Amazon and SpaceX are still blasting off
    • Smallest.ai raises $13M to build ultra-fast voice AI that sounds genuinely human
    • Repeat founder Ryan Williams raises $10M seed for an AI startup for private credit managers
    • Fusion power darling Commonwealth Fusion Systems raises another $1B
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Cyber Reality - Chinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave
    Cyber Reality

    Chinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave

    TechurzBy TechurzOctober 8, 2025Updated:May 10, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Chinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Oct 08, 2025Ravie LakshmananMalware / Threat Intelligence

    Threat actors with suspected ties to China have turned a legitimate open-source monitoring tool called Nezha into an attack weapon, using it to deliver a known malware called Gh0st RAT to targets.

    The activity, observed by cybersecurity company Huntress in August 2025, is characterized by the use of an unusual technique called log poisoning (aka log injection) to plant a web shell on a web server.

    “This allowed the threat actor to control the web server using ANTSWORD, before ultimately deploying Nezha, an operation and monitoring tool that allows commands to be run on a web server,” researchers Jai Minton, James Northey, and Alden Schmidt said in a report shared with The Hacker News.

    In all, the intrusion is said to have likely compromised more than 100 victim machines, with a majority of the infections reported in Taiwan, Japan, South Korea, and Hong Kong.

    The attack chain pieced together by Huntress shows that the attackers, described as a “technically proficient adversary,” leveraged a publicly exposed and vulnerable phpMyAdmin panel to obtain initial access, and then set the language to simplified Chinese.

    The threat actors have been subsequently found to access the server SQL query interface and run various SQL commands in quick succession in order to drop a PHP web shell in a directory accessible over the internet after ensuring that the queries are logged to disk by enabling general query logging.

    “They then issued a query containing their one-liner PHP web shell, causing it to be recorded in the log file,” Huntress explained. “Crucially, they set the log file’s name with a .php extension, allowing it to be executed directly by sending POST requests to the server.”

    The access afforded by the ANTSWORD web shell is then used to run the “whoami” command to determine the privileges of the web server and deliver the open-source Nezha agent, which can be used to remotely commandeer an infected host by connecting to an external server (“c.mid[.]al”).

    An interesting aspect of the attack is that the threat actor behind the operation has been running their Nezha dashboard in Russian, with over 100 victims listed across the world. A smaller concentration of victims is scattered across Singapore, Malaysia, India, the U.K., the U.S., Colombia, Laos, Thailand, Australia, Indonesia, France, Canada, Argentina, Sri Lanka, the Philippines, Ireland, Kenya, and Macao, among others.

    The Nezha agent enables the next stage of the attack chain, facilitating the execution of an interactive PowerShell script to create Microsoft Defender Antivirus exclusions and launch Gh0st RAT, a malware widely used by Chinese hacking groups. The malware is executed by means of a loader that, in turn, runs a dropper responsible for configuring and starting the main payload.

    “This activity highlights how attackers are increasingly abusing new and emerging publicly available tooling as it becomes available to achieve their goals,” the researchers said.

    “Due to this, it’s a stark reminder that while publicly available tooling can be used for legitimate purposes, it’s also commonly abused by threat actors due to the low research cost, ability to provide plausible deniability compared to bespoke malware, and likelihood of being undetected by security products.”

    Attack Chinese Hackers Nezha opensource Tool wave Weaponize
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWhy the new H-1B policy helps outsourcers, not startups
    Next Article We grabbed the 100+ best deals for Prime Day 2: Discounts up to 56% off on TVs, Kindles, & more
    Techurz
    • Website

    Related Posts

    Opinion

    Arcee, a US open source AI lab, says Chinese models are not inherently dangerous

    July 22, 2026
    Opinion

    Popular open source AI developer tool Ollama raises $65M, grows to nearly 9M users

    July 9, 2026
    Opinion

    Quantum Space’s military SPAC is trying to catch SpaceX’s IPO wave

    June 11, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.