
From Exposed phpMyAdmin to Full Server Takeover: Anatomy (and Defense) of the Nezha → Ghost RAT Chain Used by China-Nexus Actors
ince August 2025, researchers have tracked a campaign chaining phpMyAdmin/MariaDB log poisoning, a China Chopper–style web shell, AntSword for post-exploitation, deployment of a Nezha (open-source RMM/monitoring) agent, and finally Ghost