Huntress researchers detail a multi-stage web intrusion campaign discovered in August 2025, attributed to a likely China-nexus threat actor. The attacker exploited an unauthenticated phpMyAdmin panel on a XAMPP server to perform log poisoning via MariaDB's general query log, writing a PHP eval web shell to a publicly accessible directory. AntSword was then used to remotely control the compromised server, download the Nezha open-source monitoring agent (first public report of Nezha being weaponized this way), and ultimately deploy a Ghost RAT variant for persistent access. The Nezha C2 dashboard revealed over 100 victim machines, predominantly in Taiwan, Japan, South Korea, and Hong Kong. A detailed malware analysis covers Ghost RAT's three-stage loader, dropper, and payload architecture, including its C2 command table and config decryption routine. IOCs including IPs, domains, hashes, and persistence artifacts are provided.