#GhostRedirector
#ESETresearch uncovers GhostRedirector, a threat actor compromising Windows servers with a C++ Backdoor named Rungan and Gamshen, a native IIS malware www.welivesecurity.com/en/eset-rese... 1/6
GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes
ESET researchers have identified a new threat actor targeting Windows servers with a passive C++ backdoor and a malicious IIS module that manipulates Google search results.
www.welivesecurity.com
September 4, 2025 at 10:06 AM
⚠️ GhostRedirector hijacks 65 Windows servers

A stealthy campaign dating back to August 2024 saw the #GhostRedirector group compromise 65 Windows servers (mainly in Brazil, Thailand, Vietnam) by deploying the Rungan backdoor for remote control and Gamshen IIS module for SEO fraud-as-a-service.
September 5, 2025 at 7:37 AM
-CISA 2015 headed for renewal
-IPTV piracy network linked to Afghan national
-Streameast taken down
-New TAG-150 group
-GhostRedirector group manipulates Google results
-New Cisco ASA reconnaissance campaign
-North Korean hackers abuse cyber intel platforms
-US offers $10mil BeserkBear reward
September 5, 2025 at 10:01 AM
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module thehackernews.com/2025/09/ghos...
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module
GhostRedirector compromised 65 Windows servers since Aug 2024 using Rungan and Gamshen malware, driving SEO fraud.
thehackernews.com
September 7, 2025 at 6:22 AM
GhostRedirector compromised 65 Windows servers since Aug 2024 using Rungan and Gamshen malware, driving SEO fraud.
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module
thehackernews.com
September 5, 2025 at 11:19 AM
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module

Cybersecurity researchers have lifted the lid on an undocumented threat cluster GhostRedirector, that has managed to compromise at least 65 Windows servers primarily!

#crimenews
thehackernews.com/2025/09/ghos...
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module
GhostRedirector compromised 65 Windows servers since Aug 2024 using Rungan and Gamshen malware, driving SEO fraud.
thehackernews.com
September 8, 2025 at 8:20 AM
A newly discovered group of threat actors, dubbed #GhostRedirector, is targeting #Windows servers to manipulate #Google #search results.

hothardware.com/news/ghostre...
Ghastly GhostRedirector Gang Is Hijacking Windows Servers For Google SEO Tricks
A newly discovered group of threat actors, dubbed GhostRedirector, is targeting Windows servers to manipulate Google search results.
hothardware.com
September 5, 2025 at 8:06 PM
GhostRedirector: O novo grupo ligado à China que ataca servidores Windows

#backdoor #google #internet #microsoft #SEO #servidor #servidores #sql #tecnologia #vulnerabilidade #windows
GhostRedirector: O novo grupo ligado à China que ataca servidores Windows
tugatech.com.pt
September 9, 2025 at 12:35 PM
GhostRedirector: How a Novel NTLM Attack Poisons Windows Servers and Plants Backdoors

Introduction: A new vulnerability dubbed "GhostRedirector" has emerged, leveraging a sophisticated NTLM relay attack to compromise Windows servers. This technique, which weaponizes misconfigured DNS and WPAD…
GhostRedirector: How a Novel NTLM Attack Poisons Windows Servers and Plants Backdoors
Introduction: A new vulnerability dubbed "GhostRedirector" has emerged, leveraging a sophisticated NTLM relay attack to compromise Windows servers. This technique, which weaponizes misconfigured DNS and WPAD settings, allows attackers to achieve remote code execution and establish persistent backdoors, posing a significant threat to enterprise networks. Learning Objectives: Understand the mechanics of the GhostRedirector NTLM relay and poisoning attack. Learn to identify and mitigate misconfigured DNS and WPAD services on a network.
undercodetesting.com
September 7, 2025 at 2:14 PM
'SEO fraud-as-a-service' scheme hijacks Windows servers to promote gambling websites therecord.media/seo-scheme-w...
'SEO fraud-as-a-service' scheme hijacks Windows servers to promote gambling websites
A malware campaign dubbed GhostRedirector by researchers at ESET attempts to compromise websites to drive traffic to gambling sites.
therecord.media
September 7, 2025 at 12:42 AM
ESET Research discovers new Chinese threat group: GhostRedirector manipulates Google, poisons Windows servers with backdoors

ESET Research has discovered a new threat actor, which it has named GhostRedirector. In June 2025, this threat actor compromised at least 65 Windows servers, mainly in…
ESET Research discovers new Chinese threat group: GhostRedirector manipulates Google, poisons Windows servers with backdoors
ESET Research has discovered a new threat actor, which it has named GhostRedirector. In June 2025, this threat actor compromised at least 65 Windows servers, mainly in Brazil, Thailand, Vietnam, and the United States. Other victims were located in Canada, Finland, India, the Netherlands, the Philippines, and Singapore. GhostRedirector used two previously undocumented, custom tools: a passive C++ backdoor that ESET has named Rungan, and a malicious Internet Information Services (IIS) module it has named Gamshen.
itnerd.blog
September 11, 2025 at 12:45 PM
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module

Cybersecurity researchers have lifted the lid on a previously undocumented threat cluster dubbed GhostRedirector that has managed to compromise at least 65 Windows servers primarily located in …

#hackernews #news
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module
Cybersecurity researchers have lifted the lid on a previously undocumented threat cluster dubbed GhostRedirector that has managed to compromise at least 65 Windows servers primarily located in Brazil, Thailand, and Vietnam. The attacks, per Slovak cybersecurity company ESET, led to the deployment of a passive C++ backdoor called Rungan and a native Internet Information Services (IIS) module
thehackernews.com
September 5, 2025 at 6:10 PM
'SEO fraud-as-a-service' scheme hijacks Windows servers to promote gambling websites #cybersecurity #hacking #news #infosec #security #technology #privacy
'SEO fraud-as-a-service' scheme hijacks Windows servers to promote gambling websites
A malware campaign dubbed GhostRedirector by researchers at ESET attempts to compromise websites to drive traffic to gambling sites.
therecord.media
September 6, 2025 at 2:05 PM
Malware abusa de vulnerabilidade no Windows pra manipular buscas do Google
Pesquisadores encontraram um **novo agente de ameaças** , nomeado **GhostRedirector**. De acordo com a **ESET** , que mapeou a atividade, o grupo atua em **mais de 65 servidores Windows** globalmente. Os alvos com maior incidência são **Brasil, Tailândia e Vietnã** – mas Estados Unidos, Canadá, Finlândia e Índia também registraram invasões. A investigação revelou que GhostRedirector usou duas técnicas não muito exploradas: um **backdoor passivo C++** , chamado de **Rungan** e um módulo malicioso de Serviços de Informações da Internet (IIS) nomeado Gamshen. ## Rungan e Gamshen: backdoor e módulo malicioso O **Rungan** é um _**backdoor**_ , ou seja, uma forma de acessar sistemas, apps e redes de forma não autorizada. O fato dele ser **desenvolvido em C++** , adiciona uma camada a mais de gravidade, uma vez que esse tipo de linguagem de código permite **controle remoto direto** sobre o **hardware** do computador. Já o **Gamshen** , funciona como um **módulo malicioso para IIS** - que é um tipo de servidor Web criado pela Microsoft para seus sistemas operacionais, que **manipula o tráfego**. Sua principal função é **detectar** quando quem está navegando na web é o **Googlebot** - um robô do Google que rastreia a internet. Assim, ele consegue**cometer fraudes de SEO**(Otimização para Mecanismos de Busca). Na prática, isso permite que os criminosos coloquem **sites fraudulentos no topo das pesquisas** , para que eles estejam entre os primeiros resultados das buscas do Google, sem alertar os usuários comuns. Para evitar serem **excluídos** por **dispositivos de segurança** , os atacantes também usam técnicas conhecidas como **EfsPotato e BadPotato**. Esses são **exploits públicos** - códigos que exploram vulnerabilidades de segurança de forma aberta. Isso torna possível que os criminosos criem **contas de administrador** , para manter o acesso mesmo após varreduras de antivírus, por exemplo. Além disso, esses **exploits** podem ser usados para baixar e executar outros componentes maliciosos com **privilégios mais altos** , tudo para evitar que eles percam acesso ao servidor invadido. > A investigação revelou que **não há um alvo certo**. Os criminosos já miraram servidores ligados à setores como **educação, saúde, seguros, transporte, tecnologia e varejo**. É possível que os principais alvos sejam apenas **sistemas vulneráveis.** Também como medida protetiva, eles instalam o **GoToHTTP**. Com esta ferramenta, os cibercriminosos têm uma**“porta de serviço” paralela** , legítima aos olhos do sistema, que permite voltar a qualquer momento, mesmo se os outros malwares forem removidos. Ou seja, o GoToHTTP é mais um jeito de**manter a invasão viva e discreta** , garantindo que o esquema de SEO fraudulento continue funcionando sem interrupções. ## Especialistas não sabem quem está por trás do esquema A ESET afirmou que **não é possível** bater o martelo em **quem está por trás** desse ataque – mas, indícios levam à**hackers chineses.** Afinal, os investigadores encontraram trechos de código em chinês, certificados digitais emitidos para empresas da China e até senhas criadas com palavras em mandarim. Para a empresa de segurança, esses detalhes são **pistas** , não provas concretas. O GhostRedirector **não é o primeiro** caso de um agente de ameaça ligado à China envolvido em fraudes de SEO por meio de módulos IIS maliciosos. No ano passado, a **Cisco Talos** identificou um agente de ameaças alinhado à China chamado **DragonRank** , que conduz fraudes em SEO. Ambos os agentes miraram em vítimas parecidas. O DragonRank foi identificado na **Tailândia e Índia** - assim como o GhostRedirector - e também na **Holanda**. Também não havia indícios de setores-alvo, já que o DragonRank atacou instituições de**saúde, transporte e TI**. Apesar dessas semelhanças, a ESET afirma que **não há razão** para acreditar que ambos os **grupos estão ligados**. ## É possível se proteger? Por não saber quem pode ser alvo dessa operação, é possível tomar algumas **precauções** - e medidas de segurança - para **evitar** intercorrências. Conforme o detalhamento da própria ESET, todos os passos, desde a instalação do Rungan, Gamshen, EfsPotato e BadPotato, ao GoToHTTP, reforçam a importância de **aplicar patches** rapidamente, **monitorar** módulos e **bloquear** acessos não autorizados. Assim, é bom adotar algumas medidas de segurança para respaldar os sistemas e evitar vulnerabilidades que possam ser exploradas. * **Atualizar Windows e IIS:** aplicar patches de segurança o quanto antes; * **Restringir exposição do IIS:** só o necessário fica acessível na internet; * **Monitorar módulos e contas:** verificar DLLs estranhas no IIS e criação de contas admin; * **Auditar logs de acesso:** checar se há respostas diferentes para o Googlebot; * **Usar EDR/antivírus no servidor:** detectar backdoors e comportamento suspeito; * **Bloquear softwares de acesso remoto** não autorizados (tipo GoToHTTP); * **Ter plano de resposta a incidentes:** manter backups prontos e equipe preparada. Se quiser saber mais sobre golpes e ataques cibernéticos, acompanhe o TecMundo nas redes sociais e no YouTube. Para receber notícias sobre tecnologia e segurança, se inscreva em nossa newsletter.
www.tecmundo.com.br
September 4, 2025 at 10:54 PM
GhostRedirector’s Gambit: Chinese Cyber Crew Hijacks Servers for Gambling SEO Fraud

GhostRedirector cybercrime crew uses malware to boost gambling sites' Google rankings. ESET researchers uncover their tactics, targeting servers worldwide.
thenimblenerd.com?p=1054725
GhostRedirector’s Gambit: Chinese Cyber Crew Hijacks Servers for Gambling SEO Fraud
GhostRedirector, the new China-aligned cybercrime crew, has hacked 65 Windows servers to boost gambling sites' Google rankings. Using two fresh malware tools - Rungan and Gamshen - these digital tricksters fool Googlebot with fake backlinks. It's like they've taken SEO from search engine optimization to sneaky espionage operation.
thenimblenerd.com
September 4, 2025 at 10:08 PM
A group of Chinese professional internet crimes manipulates SEO to increase gambling sites

ESET researchers have revealed a professional group of Chinese electronic crimes that treat search engines (SEO) to enhance traffic on gambling sites. The bad actor, called Ghostredirector by ESET, may be at…
A group of Chinese professional internet crimes manipulates SEO to increase gambling sites
ESET researchers have revealed a professional group of Chinese electronic crimes that treat search engines (SEO) to enhance traffic on gambling sites. The bad actor, called Ghostredirector by ESET, may be at least at least 65 Windows server in Brazil, Thailand and Vietnam. Researchers claim that the group uses two dedicated tools: it is a negative C ++ inheritance that they called Rungan, and the IIS Malver Internet Information Services Unit (IIS) called Gamshen. Rungan can carry out orders on a speaker at risk, while GAMSAN can perform SEO search engines to process the search engine results.
star-news.press
September 6, 2025 at 9:04 AM
中国のハッカー、Googleを操作してギャンブルサイトを強化

出典: Dave Hoeek / Shutterstock 中国を拠点とする可能性が高いプロのサイバー犯罪組織が、さまざまなギャンブルサイトの検索順位を人工的に引き上げることを目的とした高度なSEO操作キャンペーンを展開しています。 ESETの研究者が「GhostRedirector」として追跡しているこの作戦は、Windows Webサーバー上で稼働しているサイトを侵害し、権限昇格や永続化、さらにはGoogleのウェブサイトインデックス用クローラーを操作するためのさまざまなマルウェアツールを仕込むものです。 広範な標的…
中国のハッカー、Googleを操作してギャンブルサイトを強化
出典: Dave Hoeek / Shutterstock 中国を拠点とする可能性が高いプロのサイバー犯罪組織が、さまざまなギャンブルサイトの検索順位を人工的に引き上げることを目的とした高度なSEO操作キャンペーンを展開しています。 ESETの研究者が「GhostRedirector」として追跡しているこの作戦は、Windows Webサーバー上で稼働しているサイトを侵害し、権限昇格や永続化、さらにはGoogleのウェブサイトインデックス用クローラーを操作するためのさまざまなマルウェアツールを仕込むものです。 広範な標的 このキャンペーンは少なくとも2024年8月から活動しているとみられ、主にブラジル、ベトナム、タイの数十のウェブサイトに影響を与えています。これまでに脅威アクターが侵害した65サイトのうち、米国拠点のものもわずかに含まれていますが、これらも主な標的国リストに本拠を置く企業のものとみられます。 ESETによると、これまで知られていなかったこの脅威アクターによる業種特有の標的化の証拠は見つかっておらず、被害者は医療、教育、運輸、保険、小売、テクノロジーなどさまざまな分野にランダムに分布しています。 GhostRedirectorの攻撃チェーンをESETが分析したところ、脅威アクターが初期アクセスを得るのは、おそらく未修正のSQLインジェクション脆弱性を悪用してWindows Webサーバーに侵入することから始まると判明しました。サーバーに侵入すると、GhostRedirectorはPowerShellを使ってさまざまなマルウェアツールをダウンロードします。その中には、ESETが「Rungan」と「Gamshen」として追跡しているこれまで見られなかった2つのツールも含まれます。権限昇格には、研究者が「EfsPotato」とBadPotatoとして追跡している既知の2つのエクスプロイトが使われています。 悪意あるIISモジュール RunganはC++で書かれたパッシブ型バックドアで、攻撃者に侵害されたWebサーバーへのリモートアクセスを与え、任意のコマンドを実行できるようにします。ESETは、Gamshenが悪意ある機能を持つネイティブInternet Information Services(IIS)コンポーネントとして実装されていることを発見しました。IISはMicrosoftのWebサーバーソフトウェアで、多くのWindowsベースのウェブサイトを支えています。IISはモジュール式アーキテクチャを採用しており、開発者は独自のWebサーバー機能を拡張・追加できます。ネイティブIISコンポーネントがインストールされると、サーバーレベルで高い権限で動作するため、検出や削除が困難です。 これはマルウェア作者が以前から利用してきた侵害後の機能であり、Windows Webサーバーを予期せぬ動作に導くことができます。ESETは2021年のホワイトペーパーで、この種のマルウェアを「サイバー犯罪、サイバースパイ活動、SEO詐欺に使われる多様な脅威クラス」と位置付けています。同社によれば、Gamshenのような悪意あるIIS拡張機能の主な目的は「侵害されたIISサーバーに届くHTTPリクエストを傍受し、これらのリクエストへのサーバーの応答方法に影響を与えること」です。 Microsoftもまた、悪意あるIIS拡張機能がもたらす広範な脅威を認識しており、攻撃者がこれらを使って重要なWebサーバーに永続的なバックドアを設置できることを警告しています。今年7月にも、Splunkが警告したように、複数の重要なSharePoint脆弱性のエクスプロイトと悪意あるIISモジュールを組み合わせ、脆弱なシステムで深い永続性を実現する脅威アクターが現れています。Microsoftによれば、IISバックドアは「主にターゲットアプリケーションが使用する正規モジュールと同じディレクトリに存在し、クリーンなモジュールと同じコード構造を持つため、検出が困難」です。多くの場合、バックドアのロジックは最小限で、追加の文脈がなければ正規の拡張機能とほとんど区別がつかないと同社は述べています。 SEOポイズニング Gamshenの明確な目的は、GhostRedirectorが宣伝したいウェブサイトへのリンクを密かに提供することです。GoogleのGooglebotが侵害されたウェブサイトをインデックスするために訪れると、Gamshenは検索エンジンクローラーを検知し、ページコンテンツ内にターゲットサイトへのリンクを挿入します。目的は、多数の正規(ただし侵害された)ウェブサイトからバックリンクを生成することで、ターゲットサイトの検索順位を人工的に引き上げることです。GhostRedirectorは、このようなSEOポイズニングを行う中国拠点の脅威アクターとしては初めてではありません。昨年、Cisco Talosが報告したように、DragonFlyという別の中国のアクターも同様の手法を同じ目的や他の目的で用い、「BadIIS」と呼ばれるマルウェアを使っていました。 ネイティブIISモジュールはWindows Webサーバーを最初に侵害しなければ導入できないため、ESETは組織に対し、IISサーバー管理者用に専用アカウント、強力なパスワード、多要素認証を使用することを推奨しています。また、管理者はネイティブIISモジュールが信頼できるソースからのみインストールされ、信頼できるプロバイダーによって署名されていることを確認するよう助言しています。 翻訳元:
blackhatnews.tokyo
September 5, 2025 at 9:06 AM
GhostRedirector-永続的なアクセスとSEO悪用 share.google/TPcb2hCwtpLH...

人万代野国JAPAN行かなきゃ...。U。ニンゲンセイエーキキキキキですネについているわけではないよネサール遠キ5キ5キ5ワンピンゲーセンタノモウSEeRrЯu
qq⭕pp👋🍌🍌🍌🍌🍌🍌🍌。U。🍌.u.
99955517229848592
Q&AuWAカドカワショウテンニコヤセイバーノモノヤッパリイラヌワグンムタントウタイサヨリ..QQ†Q†pp
α/@ エンド Ω/ω
EEカドマツタノヤバンザイクウキナリーerroRrЯrcord
July 20, 2026 at 11:44 AM
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module

Cybersecurity researchers have lifted the lid on a previously undocumented threat cluster dubbed GhostRedirector that has managed to compromise at least 65 Windows servers primarily located in Brazil, Thailand,…
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module
Cybersecurity researchers have lifted the lid on a previously undocumented threat cluster dubbed GhostRedirector that has managed to compromise at least 65 Windows servers primarily located in Brazil, Thailand, and Vietnam. The attacks, per Slovak cybersecurity company ESET, led to the deployment of a passive C++ backdoor called Rungan and a native Internet Information Services (IIS) module codenamed Gamshen. The threat actor is believed to be active since at least August 2024.
nexttech-news.com
September 5, 2025 at 5:33 AM
GhostRedirector攻击暴露:揭秘使用Rungan后门和Gamshen IIS模块入侵65台Windows服务器的全貌

https://qian.cx/posts/FB28133B-5521-41D9-8AD8-DAB63B1F8D96
December 15, 2025 at 7:33 PM
中国拠点と思われるハッカーグループGhostRedirectorが、少なくとも65台のWindowsサーバーをハッキングし、SEO詐欺を行っている。2つの新しいバックドアを使い、カジノサイトへのアクセスを増やすためにGoogleの検索順位を操作していた。 therecord.media/seo-scheme-w...
'SEO fraud-as-a-service' scheme hijacks Windows servers to promote gambling websites
A malware campaign dubbed GhostRedirector by researchers at ESET attempts to compromise websites to drive traffic to gambling sites.
therecord.media
September 5, 2025 at 12:48 PM