logo

China-aligned crew poisons Windows servers to manipulate Google results

ID: 8f200881-6557-518f-b995-4d64d7f23c6b

STIX ID: report--8f200881-6557-518f-b995-4d64d7f23c6b

Feed Name: The Register (Security)

Threat Score
68/100

Date Published: 2025-09-04

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

GhostRedirector, a China-aligned cybercrime crew, has compromised at least 65 Windows servers across multiple countries since mid-2024 using probable SQL injection for initial access, potato-family privilege escalation, and custom malware (Rungan backdoor and Gamshen IIS trojan) to perform SEO fraud by altering responses for Googlebot and boosting gambling sites' rankings; additional tools observed include Comdai and Zunput and some payloads were validly code-signed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.