GhostRedirector is a previously undocumented threat cluster reported by ESET that has been active since at least August 2024. The actor compromised at least 65 Windows servers, primarily in Brazil, Thailand, and Vietnam, and targeted IIS servers. ESET reported that GhostRedirector deployed a passive C++ backdoor named Rungan and a malicious IIS module codenamed Gamshen. Gamshen was assessed to facilitate SEO fraud, including manipulation of search engine results, and was described as providing SEO fraud-as-a-service. Public reporting places GhostRedirector among multiple China-linked or China-aligned clusters that have targeted IIS servers over the past year, alongside groups such as CL-STA-0048, DragonRank, Operation Rewrite, and UAT-8099. However, available reporting also states GhostRedirector should be treated as a distinct adjacent cluster unless its specific hallmarks are present, including Rungan, Gamshen, and associated domains. Known alias in the provided content: GhostRedirector.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named China-linked operation previously observed targeting IIS servers.
China-aligned threat group observed targeting IIS web servers.
Cluster compromising Windows servers (noted in Brazil/Thailand/Vietnam) deploying Rungan backdoor and Gamshen IIS module for persistence/traffic manipulation.
Separate IIS SEO-fraud/redirector activity cluster in the same problem space; treated as low-probability match to UAT-8099/WEBJACK unless specific GhostRedirector hallmarks (e.g., Rungan/Gamshen artifacts and associated domains) are present.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.