GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes
ID: e19044b3-5bd7-51f9-a0b8-0574239464ca
STIX ID: report--e19044b3-5bd7-51f9-a0b8-0574239464ca
Feed Name: WeLiveSecurity (ESET Research)
ESET documents GhostRedirector, a previously unknown China-aligned threat actor active since 2024 that has compromised at least 65 Windows servers across multiple countries by exploiting public-facing applications (likely SQL injection) and using PowerShell to deploy tools; the actor deploys privilege-escalation utilities (EfsPotato/BadPotato variants), creates administrative accounts, installs webshells and a passive C++ backdoor (Rungan), and a native IIS module (Gamshen) to perform SEO fraud and manipulate Google search results; the report provides IoCs, infrastructure details, MITRE mappings and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
