China-aligned crew poisons Windows servers to manipulate Google results
ID: 8f200881-6557-518f-b995-4d64d7f23c6b
STIX ID: report--8f200881-6557-518f-b995-4d64d7f23c6b
Feed Name: The Register (Security)
Threat Score
GhostRedirector, a China-aligned cybercrime crew, has compromised at least 65 Windows servers across multiple countries since mid-2024 using probable SQL injection for initial access, potato-family privilege escalation, and custom malware (Rungan backdoor and Gamshen IIS trojan) to perform SEO fraud by altering responses for Googlebot and boosting gambling sites' rankings; additional tools observed include Comdai and Zunput and some payloads were validly code-signed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
