'SEO fraud-as-a-service' scheme hijacks Windows servers to promote gambling websites
ID: 45b8c65b-6cd3-5a01-9e86-9c77268bc7b0
STIX ID: report--45b8c65b-6cd3-5a01-9e86-9c77268bc7b0
Feed Name: The Record from Recorded Future News
ESET researchers identified GhostRedirector, a likely China-aligned actor active since at least August 2024 that has breached at least 65 Windows servers across multiple countries and industries. The group deployed two novel backdoors—Rungan for remote command execution and Gamshen embedded in IIS to covertly boost gambling sites' Google rankings—using public exploits and privileged accounts; the immediate impact is SEO fraud and reputational harm, though the Rungan backdoor could enable additional malicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
