GhostRedirector is malware referred to in the provided content as an IIS module, commonly appearing in the analytic story name "GhostRedirector IIS Module and Rungan Backdoor." The available material does not provide a full malware report, but it consistently associates GhostRedirector with abuse of Microsoft IIS components and web-server persistence tradecraft. Specifically, the content links it to MITRE ATT&CK technique T1505.004 (IIS Components), including detections for adding new IIS modules, WebGlobalModule usage, querying installed global modules, module load failures, adding assemblies to the Global Assembly Cache with GACUtil, and disabling HTTP logging. The content also places GhostRedirector in contexts involving exploitation of public-facing applications and web-shell or web-server post-exploitation detections, including Confluence, Ivanti, Exchange web shell, suspicious child processes spawned from web servers, and web or application server processes spawning shells. Additional references associate the GhostRedirector story with remote access software usage, Windows privilege escalation, SQL Server abuse such as xp_cmdshell configuration changes, obfuscated or malicious PowerShell activity, file download via PowerShell, msiexec network communication, curl downloads to suspicious paths, CertUtil decode usage, and RAR SFX file creation. High-confidence information directly present in the content is limited to these defensive and analytic associations; the content does not explicitly identify an infection vector, operator, specific victim sectors, or concrete IOCs for GhostRedirector beyond its repeated characterization as an IIS module tied to the "GhostRedirector IIS Module and Rungan Backdoor" analytic story.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Detect Exchange Web Shell ... BlackByte Ransomware, Seashell Blizzard, GhostRedirector IIS Module and Rungan Backdoor
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious IIS module referenced in an associated analytic story.
GhostRedirector is referenced as an IIS module in an associated analytic story, suggesting server-side persistence or redirection capability.
GhostRedirector is referenced as a malicious IIS module associated with web server compromise and persistence.
Associated Analytic Story GhostRedirector IIS Module and Rungan Backdoor
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.