Drooid Logo
Back to story perspectives

Full Breakdown

GhostRedirector: A New China-Aligned Cyber Threat Targeting Windows Servers

9/5/2025, 10:01:29 PM

Overview of the GhostRedirector Campaign

Cybersecurity researchers have identified a new threat group named GhostRedirector, which has compromised at least 65 Windows servers across multiple countries, primarily in Brazil, Thailand, Vietnam, and the United States. This group has been active since at least August 2024, with significant activity noted between December 2024 and June 2025. The attacks leverage two previously undocumented malware tools: a passive C++ backdoor called Rungan and a malicious Internet Information Services (IIS) module known as Gamshen. These tools are designed to manipulate search engine rankings, particularly for gambling websites, through a scheme described as SEO fraud-as-a-service.

Mechanisms of Attack

GhostRedirector gains initial access to target networks by exploiting vulnerabilities, likely SQL injection flaws. Once inside, attackers utilize PowerShell to download additional malicious tools from a staging server, identified as "868id[.]com." Rungan allows attackers to execute commands on the compromised servers, while Gamshen modifies HTTP responses specifically for Googlebot, thereby boosting the rankings of targeted gambling sites. This manipulation involves creating artificial backlinks from the compromised websites to the gambling sites, misleading search engines into perceiving the latter as reputable.

Tools and Techniques

In addition to Rungan and Gamshen, GhostRedirector employs various other tools, including:

  • GoToHTTP: Establishes remote connections accessible via web browsers.
  • Zunput: Gathers information about websites hosted on the IIS server and deploys web shells.
  • EfsPotato and BadPotato: Publicly known exploits used for privilege escalation, allowing the creation of privileged user accounts on the compromised servers.

These tools enable the attackers to maintain long-term access and operational resilience, ensuring they can execute privileged operations even if some malware is removed.

Targeted Sectors and Global Reach

The victims of GhostRedirector span a diverse range of sectors, including education, healthcare, insurance, transportation, technology, and retail. While the majority of compromised servers are located in Brazil, Peru, Thailand, Vietnam, and the United States, smaller clusters have been identified in Canada, Finland, India, the Netherlands, the Philippines, and Singapore. This indiscriminate targeting underscores the group's broad operational scope.

Attribution and Implications

ESET researchers assess with medium confidence that GhostRedirector is aligned with China, citing indicators such as hard-coded Chinese strings in the malware's source code, a code-signing certificate from a Chinese company, and the use of a Mandarin password. This activity is reminiscent of another China-linked group, DragonRank, which has also engaged in SEO manipulation.

Criticism & Opposition

Critics have raised concerns about the potential long-term damage to the reputation of compromised organizations, even if end-users are not directly harmed. The manipulation of search rankings can erode trust in legitimate businesses, highlighting the need for enhanced cybersecurity measures.

Official Statements & Recommendations

ESET emphasizes the importance of securing public-facing Windows servers, particularly those running IIS. Recommendations include regularly patching vulnerabilities, monitoring for unusual PowerShell activity, implementing strict access controls, and auditing user accounts for unauthorized changes.

Verbatim Quotes

  • “Gamshen abuses the credibility of the websites hosted on the compromised server to promote a third-party, gambling website – potentially a paying client participating in an SEO fraud as-a-service scheme,” — Fernando Tavella, ESET Researcher
  • “GhostRedirector attempts to manipulate the Google search ranking of a specific, third-party website by using manipulative, shady SEO techniques such as creating artificial backlinks from the legitimate, compromised website to the target website,” — Fernando Tavella, ESET Researcher

The emergence of GhostRedirector serves as a critical reminder of the evolving landscape of cyber threats and the necessity for organizations to bolster their defenses against such sophisticated attacks.