Huntress researchers detail a multi-stage web intrusion campaign discovered in August 2025, attributed to a likely China-nexus threat actor. The attacker exploited an unauthenticated phpMyAdmin panel on a XAMPP server to perform log poisoning via MariaDB's general query log, writing a PHP eval web shell to a publicly accessible directory. AntSword was then used to remotely control the compromised server, download the Nezha open-source monitoring agent (first public report of Nezha being weaponized this way), and ultimately deploy a Ghost RAT variant for persistent access. The Nezha C2 dashboard revealed over 100 victim machines, predominantly in Taiwan, Japan, South Korea, and Hong Kong. A detailed malware analysis covers Ghost RAT's three-stage loader, dropper, and payload architecture, including its C2 command table and config decryption routine. IOCs including IPs, domains, hashes, and persistence artifacts are provided.

22m read timeFrom huntress.com
Post cover image
Table of contents
Background / SummaryIn-Depth threat analysisNezha: A new RMM tool enters the chatVictimologyGhost RAT in the machineGhost RAT implant analysisSubdomain insightsConclusionIOCs