Chinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave
Threat actors suspected of having ties to China have transformed Nezha, a valid open-source monitoring tool, into an attack weapon that they use to infect targets with Gh0st RAT, a known malware.
The behavior, which was noticed by cybersecurity firm Huntress in August 2025, is typified by the installation of a web shell on a web server using an uncommon method known as log poisoning, also known as log injection.
Researchers Jai Minton, James Northey, and Alden Schmidt said in a study shared with The Hacker News that this enabled the threat actor to use ANTSWORD to take control of the web server before finally launching Nezha, an operating and monitoring tool that enables instructions to be run on a web server.
The majority of the infections were detected in Taiwan, Japan, South K...

