GhostRedirector is a China-aligned threat cluster, assessed with medium confidence, active since at least August 2024. It has compromised Windows servers running Microsoft Internet Information Services (IIS), principally in Brazil, Thailand, and Vietnam. The group deploys the Rungan passive C++ backdoor and the Gamshen malicious IIS module. Gamshen supports SEO fraud-as-a-service by manipulating search-engine results to promote gambling-related websites. GhostRedirector is part of a broader set of China-linked or Chinese-speaking operations that target IIS infrastructure for SEO manipulation, but it is tracked as a distinct cluster from DragonRank, CL-STA-0048, Operation Rewrite, and UAT-8099/WEBJACK.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A China-aligned actor assessed by ESET that compromises Windows IIS servers and deploys the Gamshen native IIS module for gambling-related SEO fraud. Gamshen selectively changes responses for Googlebot while leaving ordinary visitors on the requested page.
Named China-linked operation previously observed targeting IIS servers.
China-aligned threat group observed targeting IIS web servers.
Cluster compromising Windows servers (noted in Brazil/Thailand/Vietnam) deploying Rungan backdoor and Gamshen IIS module for persistence/traffic manipulation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.