Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Nezha monitoring tool were weaponized by Chinese hackers in a new attack wave

Some LET members, me included, use nezha as their servers monitoring tool. Recently, there was an attack to exploit bug in the tool to distribute malware. This attack seems to target windows servers, not sure if it's also used to attack linux servers or not. The blog post doesn't give more information about whether this exploit has been patched either :|
Maybe it's best that we stop all the agents for now and wait for more information.

What are you using to monitor your chickens?

Source: https://www.huntress.com/blog/nezha-china-nexus-threat-actor-tool

«1

Comments

  • olokeoloke Member, Host Rep
    edited October 2025

    @zGato important news don't miss

  • I've been using Komari lately and it's been great.
    You might want to give it a try.
    https://github.com/komari-monitor/komari

    Thanked by 1oloke
  • @zGato said: it's over

    Let's just pray that it's not used to attack linux servers :p

  • Thanked by 1COLBYLICIOUS
  • Beszel

    Thanked by 2jnd vastness4594
  • @zGato still important news don't miss

    Thanked by 1zGato
  • There is no difference, any open source project with remote manipulation features can be used maliciously, even the rustdesk project. (rustdesk has been used illegally by so many scamming criminals that a warning label had to be added to the description).

    Thanked by 1sillycat
  • @spiritlhl said: There is no difference, any open source project with remote manipulation features can be used maliciously, even the rustdesk project. (rustdesk has been used illegally by so many scamming criminals that a warning label had to be added to the description).

    This is different. This was an attack to exploit the tool which is normally used to monitor servers to distribute malware.

  • It is very dangerous to have a built-in default account with high privileges.
    Users should be required to set a complex password during installation.

  • BetaRacksBetaRacks Member
    edited October 2025

    https://www.peeringdb.com/ix/4316
    @gugumnt
    I believe this friend is also a member of let, just using a different username.

  • grittygritty Member
    edited October 2025

    After reading the blog, it seems that hackers exploited a vulnerability in phpMyAdmin to gain access and then used Nezha to manage all the compromised machines

  • @gritty said: After reading the blog, it seems that hackers exploited a vulnerability in phpMyAdmin to gain access and then used Nezha to manage all the compromised machines

    Yeah it seems like the nezha tool itself is not the target here, you need to gain access first via the vulnerable outdated phpMyAdmin, and then use nezha to distribute malware. If you only have nezha running and nothing else there is nothing to attack?

  • jsgjsg Member, Resident Benchmarker

    Windows, phpAdmin, some stuff make-shifted , uhm, programmed by some crowd of foss devs in, from what I see, a typical web-"developer" style (in Go) + careless users ... and then some company trying to (a) make themselves look like smart sleuths, and (b) politicize the whole clusterfuck in the linked blog post.

    Sorry but the victims had it coming, in fact they almost begged for it.

  • jndjnd Member
    edited October 2025

    I generally avoid any Chinese tools, monitoring or not. Also I'm wary of random github projects that can be knowingly or unknowingly (security issues) hijacked in the future. This especially applies for management panels and monitoring tools with self-updating agents (some of them require root privilege for some features). So far I use Beszel but for important servers with production stuff or important personal services I rather trust Hetrixtools.

  • @cosmossofa said: Beszel
    @jnd said: I generally avoid any Chinese tools, monitoring or not. Also I'm wary of random github projects that can be knowingly or unknowingly (security issues) hijacked in the future. This especially applies for management panels and monitoring tools with self-updating agents (some of them require root privilege for some features). So far I use Beszel but for important servers with production stuff or important personal services I rather trust Hetrixtools.

    Thanks for the suggestion. I think I'll switch to Beszel as well. I only have a few servers, super easy to make the switch unlike @zGato :D

  • grittygritty Member
    edited October 2025

    @vastness4594 said:

    @gritty said: After reading the blog, it seems that hackers exploited a vulnerability in phpMyAdmin to gain access and then used Nezha to manage all the compromised machines

    Yeah it seems like the nezha tool itself is not the target here, you need to gain access first via the vulnerable outdated phpMyAdmin, and then use nezha to distribute malware. If you only have nezha running and nothing else there is nothing to attack?

    Yes, before reading the blog, I thought Nezha had a vulnerability. After reading it, I realized that it wasn't Nezha that had a vulnerability, but rather that phpMyAdmin should be phased out as soon as possible :D

  • truemagictruemagic Member
    edited October 2025

    I was using komari and had webssh disabled for agents. It's scary that if you used the default command to install komari-agent you can actually run linux commands from the komari server! I'm not sure whether you can even run as remote-ssh rm -rf / from the server to agents :p

    But now I removed komari and its agents as well to be safe.

  • LeviLevi Member
    edited October 2025

    How’s your reading ability? Nezha monitoring was used to monitor threat actor C2 servers. The main problem was with pma and log poisoning. Holy moly, use AI to do text summary if have no patience to read article. And article it-self is skimmed milk, just advertisement of “security services”.

    Thanked by 1satorik
  • Give me back my 5 minutes

  • If you need more clickbait title you should use the company name where C2 server was hosted, duh.

    or not as it will be deleted :-D

    Thanked by 2sillycat satorik
  • emghemgh Member, Megathread Squad

    people will do anything to not have to setup grafana

    Thanked by 4tentor jnd oloke rcy026
  • @emgh said: people will do anything

    Anything for $200

  • @zGato I know you already got tagged but I wanted to do this too.

    Thanked by 2oloke zGato
  • tentortentor Member, Host Rep

    @COLBYLICIOUS said:
    I know you already got tagged but I wanted to do this too.

    Please stop bullying my gato

    Thanked by 2zGato COLBYLICIOUS
  • @tentor said:

    @COLBYLICIOUS said:
    I know you already got tagged but I wanted to do this too.

    Please stop bullying my gato

    🫂

    Thanked by 2tentor COLBYLICIOUS
  • NeoonNeoon Community Contributor, Veteran

    Windows the fuck, on LET? maybe Nodeseek.

  • I use HetrixTools, it's nice.

    Thanked by 1COLBYLICIOUS
  • @gremeyer said:
    I use HetrixTools, it's nice.

    Never heard of them. are they good?

    Thanked by 1COLBYLICIOUS
Sign In or Register to comment.