{"id":9413,"date":"2025-12-23T10:04:37","date_gmt":"2025-12-23T10:04:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/23\/threat-actors-weaponizing-nezha-monitoring-tool-as-remote-access-trojan\/"},"modified":"2025-12-23T10:04:37","modified_gmt":"2025-12-23T10:04:37","slug":"threat-actors-weaponizing-nezha-monitoring-tool-as-remote-access-trojan","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/23\/threat-actors-weaponizing-nezha-monitoring-tool-as-remote-access-trojan\/","title":{"rendered":"Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan"},"content":{"rendered":"<p>    Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Researchers at Ontinue\u2019s Cyber Defense Center have uncovered a significant threat as attackers exploit Nezha, a legitimate open-source server monitoring tool, for post-exploitation access.<\/p>\n<p>The discovery reveals how sophisticated threat actors repurpose benign software to gain complete control over compromised systems while evading traditional security detection mechanisms.<\/p>\n<p>Nezha, originally developed for the Chinese <a href=\"https:\/\/cybersecuritynews.com\/sleeping-bouncer-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">IT community<\/a>, has garnered nearly 10,000 stars on GitHub and serves legitimate administrators in monitoring multiple servers, tracking resource usage, and performing remote maintenance.<\/p>\n<p>The tool\u2019s architecture comprises a central dashboard server coordinating lightweight agents deployed across monitored systems, enabling system health observation, command execution, file transfer, and interactive terminal sessions.<\/p>\n<p>However, these same capabilities that make Nezha valuable for legitimate use have made it an attractive target for malicious actors seeking undetected remote access.<\/p>\n<p>Ontinue analysts and researchers <a href=\"https:\/\/www.ontinue.com\/resource\/nezha-the-monitoring-tool-thats-also-a-perfect-rat\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the malware being weaponized during a post-exploitation incident investigation.<\/p>\n<p>A deployment bash script revealed the attacker\u2019s infrastructure details, including command and control server addresses, authentication tokens, and a disabled TLS configuration.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgOhffAwaTakGGWdty0pqbUhZT6z6bE7spgTUPJ1ixE-57u0SDTMB8f4yg7-6FeLWDeXqrRfNa2ugaLcCSKZr8r6gjZ8ufskJ0vGb71gwev7DYzU4-0fXoS9HAdaic2eJLE_G4YLwN3c-5ijOZH2hCPdjjw9F9sovXW56TRPBLC0QyVcYGGLz6mp6dt3eI\/s16000\/Client-server%2520model%2520%28Source%2520-%2520Ontinue%29.webp?ssl=1\" alt=\"Client-server model (Source - Ontinue)\"><figcaption class=\"wp-element-caption\">Client-server model (Source \u2013 Ontinue)<\/figcaption><\/figure>\n<\/div>\n<p>The script contained naturally written Chinese-language status messages, suggesting a native speaker authored it.<\/p>\n<p>Significantly, the threat actors managed to compromise hundreds of endpoints using this technique, demonstrating the scale of the threat.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-the-threat-actor-s-deployment-strategy\"><strong>The Threat Actor\u2019s Deployment Strategy<\/strong><\/h2>\n<p>The attacker\u2019s approach demonstrates sophisticated operational tradecraft. The bash script included configuration parameters pointing to a C2 server hosted on Alibaba Cloud services at IP address 47.79.42.91, geolocalised to Japan.<\/p>\n<p>Installation occurred silently on target systems, with detection only triggering when attackers executed commands through the agent. Ontinue researchers accessed the threat actor\u2019s dashboard in a <a href=\"https:\/\/cybersecuritynews.com\/3-soc-metrics-improved-with-sandbox-analysis\/\">sa<\/a><a href=\"https:\/\/cybersecuritynews.com\/3-soc-metrics-improved-with-sandbox-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">n<\/a><a href=\"https:\/\/cybersecuritynews.com\/3-soc-metrics-improved-with-sandbox-analysis\/\">dbox<\/a> environment, discovering the full scope of compromised infrastructure.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiV06VrymAW0EDyL9Qhi91dtDaYTVq0saYLOdCiA60twt9Sh3A5BuSMaMq5oc5w2kb2hzCmL0yanGjpnHrwkSx9FdRMGtwEkf5_j9ysaFYJbwb0SEg72DZsWygBOmSoK60gzX1auPzZDXqvicn0GpQgyxzQHlngCignjbCzY8BZWuKoh7-HLjgNW59wB-s\/s16000\/Agent%2520process%2520%28Source%2520-%2520Ontinue%29.webp?ssl=1\" alt=\"Agent process (Source - Ontinue)\"><figcaption class=\"wp-element-caption\">Agent process (Source \u2013 Ontinue)<\/figcaption><\/figure>\n<\/div>\n<p>What makes Nezha particularly dangerous is that when deployed, the agent runs with SYSTEM privileges on Windows and root access on Linux.<\/p>\n<p>This occurs because the agent requires elevated permissions to read system metrics and manage processes.<\/p>\n<p>When attackers request terminal sessions, inherited process context ensures shell access operates with full administrative capabilities. This eliminates any privilege escalation requirements that might otherwise alert defenders.<\/p>\n<p>The legitimate binary achieved zero detections across 72 security vendors on VirusTotal because it genuinely is <a href=\"https:\/\/cybersecuritynews.com\/pure-malware-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">legitimate software<\/a> pointed at attacker infrastructure. Detection evasion becomes trivial when the actual binary contains no malicious code, only misconfigured C2 endpoints.<\/p>\n<p>File management, command execution, and interactive terminal capabilities provide complete post-compromise control without requiring additional tools or custom payload development.<\/p>\n<p>Organisations should immediately hunt for Nezha presence and implement behavioural monitoring to identify suspicious terminal activity and file operations indicating compromise.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 93%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-weaponizing-nezha-monitoring-tool\/\">Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/threat-actors-weaponizing-nezha-monitoring-tool\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat Actors Weaponizing Nezha Monitoring Tool as Remote Access Trojan Researchers at Ontinue\u2019s Cyber Defense Center have uncovered a significant threat as attackers exploit Nezha, a legitimate open-source server monitoring tool, for post-exploitation access. The discovery reveals how sophisticated threat actors repurpose benign software to gain complete control over compromised systems while evading traditional security [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-9413","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9413"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9413"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9413\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9413"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9413"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9413"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}