A newly discovered group of threat actors, dubbed #GhostRedirector, is targeting #Windows servers to manipulate #Google #search results.
hothardware.com/news/ghostre...
GhostRedirector compromette server Windows con backdoor passive e modulo IIS per frodi SEO, erodendo reputazione e sicurezza degli host.
#apt #cina #GhostRedirector
www.matricedigitale.it/2025/09/05/g...
Chinese hackers hijack Windows servers to boost gambling rankings
GhostRedirector compromised 65 Windows servers since Dec 2024, installing Rungan backdoor and Gamshen IIS trojan to inject gambling backlinks for Googlebot, mainly in Latin America. Read more: getnews.me/chinese-hackers-hijack-w... #ghostredirector #seo
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module reconbee.com/ghostredirec...
#GhostRedirector #windows #RunganBackdoor #GamshenIISmodule #cyberattack
⚠️ GhostRedirector hijacks 65 Windows servers
A stealthy campaign dating back to August 2024 saw the #GhostRedirector group compromise 65 Windows servers (mainly in Brazil, Thailand, Vietnam) by deploying the Rungan backdoor for remote control and Gamshen IIS module for SEO fraud-as-a-service.
China-aligned crew poisons #Windows servers to manipulate #Google results
www.theregister.com/2025/09/04/n...
#GhostRedirector #potatoCrime crew using previously undocumented #Rungan #malware.
#PotatoSecurity #InfoSec #ThreatIntelligence #SEOpoisoning #SEOfraud
China-aligned crew poisons #Windows servers to manipulate #Google results
www.theregister.com/2025/09/04/n...
#GhostRedirector #cyberCrime crew using previously undocumented #Rungan #malware.
#CyberSecurity #InfoSec #ThreatIntelligence #SEOpoisoning #SEOfraud
GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module
thehackernews.com/2025/09/ghos...
#Infosec #Security #Cybersecurity #CeptBiro #GhostRedirector #WindowsServers #Rungan #Backdoor #Gamshen #IISModule