GhostRedirector: A New China-Aligned Threat Targeting Windows Servers

1 min read
Source: WeLiveSecurity
GhostRedirector: A New China-Aligned Threat Targeting Windows Servers
Photo: WeLiveSecurity
TL;DR Summary

ESET researchers uncovered GhostRedirector, a China-aligned threat actor that compromised at least 65 Windows servers mainly in Brazil, Thailand, and Vietnam, using custom tools like the passive backdoor Rungan and the malicious IIS module Gamshen to facilitate SEO fraud and maintain persistent access, with activities dating back to at least August 2024.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

21 min

vs 22 min read

Condensed

99%

4,35152 words

Want the full story? Read the original article

Read on WeLiveSecurity