Security researchers at Ontinue’s Cyber Defense Center have discovered that attackers are misusing Nezha, a legitimate open-source monitoring utility, as a stealthy post-exploitation remote access tool.
The threat was uncovered during an incident investigation in which adversaries deployed a Bash script to install Nezha on a compromised device silently.
Once active, the agent connected to attacker-controlled infrastructure, providing SYSTEM or root-level access without triggering security alerts.
Nezha, developed for the Chinese IT community and boasting nearly 10,000 GitHub stars, is widely used by administrators to manage multiple servers, track resources, receive alerts, and perform remote maintenance.
It’s legitimate architecture features a central dashboard server coordinating lightweight agents installed on monitored systems.
Administrators can view system health, execute commands, transfer files, and maintain interactive terminal sessions. Unfortunately, these same capabilities make Nezha highly attractive to attackers seeking complete control over compromised environments.
Transforming Legitimate Features into Weaponized Access
Continue’s SOC identified the malicious deployment via a script that included Chinese-language status messages and a hardcoded authentication secret, enabling automatic registration on an attacker’s dashboard.
The command-and-control infrastructure was found hosted on Alibaba Cloud, with the domain resolving to an IP range (47.79.40.0/21) attributed to Alibaba’s network.
Analysis showed that hundreds of endpoints were connected to the attacker’s Nezha dashboard a sign of widespread compromise.
VirusTotal scans revealed zero detections across 72 vendors, as the tool itself remains legitimate and unmodified. Security products cannot classify it as malware because malicious intent stems from usage rather than code.

Ontinue’s testing confirmed that the Nezha agent, by design, runs with elevated privileges. On Windows systems, it runs as “NT AUTHORITY\SYSTEM,” while on Linux it runs as root, granting complete administrative control without privilege escalation.
The communication channel multiplexes HTTP and gRPC traffic on the same port (by default 8008), often without TLS, mimicking legitimate monitoring traffic and evading signature-based detection.
Global Abuse and Defensive Guidance
This incident mirrors patterns previously documented by Huntress in October 2025, which observed similar abuse of Nezha across East Asia.
Continue warns that the growing use of legitimate remote management tools for malicious control highlights the limitations of traditional antivirus models.
The organization recommends proactive hunting for Nezha agents, strict authorization of remote monitoring tools, and behavior-based detection strategies.
Security teams are advised to deploy Microsoft Defender for Endpoint, enable Tamper Protection, and apply Attack Surface Reduction policies to block post-exploitation activities.
Ontinue has released detailed hunting queries and indicators of compromise through its public GitHub repository. The case reinforces a critical reality in modern cybersecurity: even legitimate software can become an attacker’s most effective weapon when operational context is ignored.
Follow us on Google News , LinkedIn and X to Get More Instant Updates, Set Cyberpress as a Preferred Source in Google.