Nezha is an open-source server monitoring, uptime monitoring, and task management tool that threat actors have repurposed as a remote access and post-exploitation implant. Reported capabilities include viewing system health, retrieving detailed information about compromised systems, executing commands, transferring files, opening interactive terminal sessions, and managing large numbers of hosts from a central dashboard. It supports multiple platforms, including Windows, Linux, macOS, and routers/openWRT devices, and its traffic can resemble normal monitoring telemetry, which may aid stealth.
The content links Nezha to multiple intrusion sets and campaigns, most notably suspected China-nexus activity. Huntress reported attackers compromising an exposed phpMyAdmin instance, abusing MariaDB general logging for log poisoning to write a PHP web shell, operating the shell with AntSword, and then deploying the Nezha agent as a foothold before disabling Microsoft Defender protections and installing a Gh0st RAT variant. Huntress assessed that more than 100 victim machines were affected, with many victims in Taiwan, Japan, South Korea, and Hong Kong. Related reporting also describes Nezha being used during compromises of vulnerable public-facing web applications and in campaigns against organizations in Southeast Asia.
Nezha also appears in post-exploitation activity following exploitation of Ivanti Endpoint Manager Mobile vulnerabilities, where attackers attempted to download the Nezha monitoring agent, sometimes with fallback to Gitee for victims in China, and in exploitation of React2Shell/CVE-2025-55182, where observed payloads included Nezha alongside Cobalt Strike beacons generated with Cross C2, FRP, Sliver, Secret-Hunter, Node.js secret-harvesting payloads, and Go-based backdoors. Blackpoint additionally reported actor-linked Nezha infrastructure in an MSP intrusion and identified a Nezha sample with SHA256 d3abd4bae082d4c9918447fe82c521567cc7f9b0e5f2d55999a6e5c40fa7fd54.
High-confidence indicators and artifacts mentioned in the content include Nezha agent/live.exe, config.yml files pointing to attacker-controlled servers, the domain c.mid[.]al resolving to 172.245.52[.]169, and Nezha-related infrastructure associated with dashboards exposing victim telemetry. The content consistently characterizes Nezha as a legitimate tool being weaponized for unauthorized remote access, persistence, monitoring, and staging of additional malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Given that attackers have previously chained stolen admin credentials from older EPMM CVEs like CVE-2026-1340, this chaining scenario is not theoretical.
Unit 42 observed widespread, automated exploitation of CVE-2026-1281 and CVE-2026-1340, two unauthenticated code injection vulnerabilities (CVSS 9.8 each) in legacy bash scripts tied to the In House Application Distribution feature.
Trend™ Research observed that CVE-2025-55182, as of this writing, is being exploited in-the-wild, and in several malware campaigns such as the emerald and nuts campaigns. ... CVE-2025-55182, which is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC) used in React.js, Next.js, and related frameworks. | Several of these are attacks that execute Cobalt Strike beacons generated with Cross C2, deploy Nezha, Fast Reverse Proxy (FRP), the Sliver payload, and the Secret-Hunter payload.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
After installing the Nezha agent, it was used to run an interactive PowerShell so that Windows Defender exclusions could be created before deploying and running another executable called x.exe.
Trend™ Research observed that CVE-2025-55182, as of this writing, is being exploited in-the-wild... a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC)... An attacker can send malicious data that executes arbitrary code on your servers before any authentication occurs.
Each of these POST requests represents the attacker’s C2 server sending instructions to the compromised web server via the deployed web shell.
Several of these are attacks that execute Cobalt Strike beacons generated with Cross C2, deploy Nezha, Fast Reverse Proxy (FRP), the Sliver payload, and the Secret-Hunter payload.
The threat actor proceeded to download a secondary payload, an executable named live.exe, and an accompanying config.yml from a website built on Cloudflare pages: rism.pages[.]dev.
live.exe was identified as an installer for a Nezha agent. Nezha is marketed as a lightweight, open-source server monitoring and task management tool... this case represents a novel finding that it is also being used to facilitate follow-on activity from web intrusions.
39 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Open-source server monitoring agent repurposed by attackers as a botnet agent on compromised Ivanti EPMM servers.
An open-source monitoring agent/platform observed as part of actor-controlled infrastructure and used during the intrusion to support remote access and monitoring of compromised systems.
Malware/backdoor referenced as a payload dropped after exploitation of Ivanti EPMM vulnerabilities, alongside miners and other backdoors.
An open-source server monitoring/management agent that attackers attempted to deploy on compromised Ivanti EPMM servers, likely to provide ongoing remote management/visibility or as a foothold utility.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.