Chinese-nexus threat actors have been observed leveraging the open-source Nezha server monitoring tool as part of a sophisticated attack campaign targeting web servers, primarily in East and Southeast Asia. The campaign, first identified by Huntress in August 2025, involves the exploitation of publicly exposed and vulnerable web applications, with a particular focus on phpMyAdmin panels. Attackers initiate the compromise by exploiting these panels, often setting the interface language to simplified Chinese, and then proceed to execute a series of SQL commands to enable general query logging. Through a technique known as log poisoning or log injection, the adversaries inject a one-liner PHP web shell into the server logs, which are deliberately configured to be saved with a .php extension, allowing remote code execution via HTTP requests. Once the web shell is established, the attackers use AntSword, a popular web shell management tool, to gain interactive control over the compromised server. With this foothold, they deploy the Nezha agent, which is typically a legitimate tool for server monitoring but in this context is repurposed to maintain persistent access and facilitate further malicious activity. The Nezha agent connects to an external command-and-control server, enabling the attackers to issue commands and monitor the infected systems covertly. Subsequently, the attackers deploy Gh0st RAT, a well-known remote access trojan, to exfiltrate data and expand their control. Analysis indicates that over 100 victim machines have been compromised in this campaign, with the majority located in Taiwan, Japan, South Korea, and Hong Kong, though similar tactics have been observed globally. The use of open-source and otherwise legitimate tools like Nezha and AntSword allows the attackers to blend in with normal network activity and evade detection by security products. This campaign underscores the growing trend of threat actors abusing publicly available tools for malicious purposes, reducing their development costs and increasing operational stealth. The technical proficiency of the attackers is evident in their ability to chain together multiple tools and techniques, from initial access to persistence and lateral movement. Security researchers emphasize the importance of securing public-facing web applications and monitoring for unusual use of legitimate administrative tools. The campaign represents the first public reporting of Nezha being used in this manner, highlighting the evolving threat landscape and the need for vigilance against the weaponization of open-source software. Organizations are advised to audit their web applications, restrict access to administrative panels, and monitor for signs of log poisoning and unauthorized tool deployment. The incident serves as a reminder that even benign tools can become potent weapons in the hands of skilled adversaries.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
Huntress publicly disclosed technical details of the campaign, including the use of log poisoning, AntSword, Nezha, Defender exclusions, and Gh0st RAT, and released indicators of compromise such as file names and paths. The report assessed the activity as likely linked to China-nexus actors but did not formally attribute it to a specific group.
In at least one investigated case, Huntress isolated the affected system and removed the web shell, Nezha agent, and Gh0st RAT payload. This response followed the attackers' use of Nezha to facilitate persistence and further malicious activity.
The campaign grew to affect over 100 machines, with victims primarily located in Taiwan, Japan, South Korea, and Hong Kong. Reporting indicates the number of affected entities was still increasing as the activity continued.
Huntress said the intrusion campaign was first detected in August 2025. The attackers exploited exposed, unauthenticated phpMyAdmin instances, abused MariaDB general query logging to create a web shell, deployed AntSword and the Nezha agent, and then delivered a Gh0st RAT variant.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
8 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesocprime.com
Open sourcescworld.com
Open sourcetherecord.media
Open sourcecsoonline.com
Open sourcedarkreading.com
Open sourcethehackernews.com
Open sourcehuntress.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.