The Crown Prince, Nezha

Reported 03 Jul 2026 by otx · Severity: medium

Beginning in August 2025, a sophisticated intrusion was discovered where attackers used log poisoning techniques to deploy a web shell on vulnerable phpMyAdmin panels. The threat actors exploited misconfigured web applications to plant China Chopper web shells, controlled via Ant