logo

GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes

ID: e19044b3-5bd7-51f9-a0b8-0574239464ca

STIX ID: report--e19044b3-5bd7-51f9-a0b8-0574239464ca

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
70/100

Date Published: 2025-09-04

Date Updated: 2026-05-01

...
...

ESET documents GhostRedirector, a previously unknown China-aligned threat actor active since 2024 that has compromised at least 65 Windows servers across multiple countries by exploiting public-facing applications (likely SQL injection) and using PowerShell to deploy tools; the actor deploys privilege-escalation utilities (EfsPotato/BadPotato variants), creates administrative accounts, installs webshells and a passive C++ backdoor (Rungan), and a native IIS module (Gamshen) to perform SEO fraud and manipulate Google search results; the report provides IoCs, infrastructure details, MITRE mappings and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.