logo

'SEO fraud-as-a-service' scheme hijacks Windows servers to promote gambling websites

ID: 45b8c65b-6cd3-5a01-9e86-9c77268bc7b0

STIX ID: report--45b8c65b-6cd3-5a01-9e86-9c77268bc7b0

Feed Name: The Record from Recorded Future News

Threat Score
65/100

Date Published: 2025-09-05

Date Updated: 2026-05-01

...
...

ESET researchers identified GhostRedirector, a likely China-aligned actor active since at least August 2024 that has breached at least 65 Windows servers across multiple countries and industries. The group deployed two novel backdoors—Rungan for remote command execution and Gamshen embedded in IIS to covertly boost gambling sites' Google rankings—using public exploits and privileged accounts; the immediate impact is SEO fraud and reputational harm, though the Rungan backdoor could enable additional malicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.