Chinese Hacker Group Compromises 65 Servers Worldwide, Targets SEO Fraud Operations

A newly identified Chinese-aligned hacking group named GhostRedirector has compromised at least 65 Windows servers worldwide, with primary targets in Brazil, Thailand, Vietnam, and the United States. The group uses two custom malware tools: Rungan, a passive C++ backdoor that allows remote command execution, and Gamshen, a malicious IIS module that manipulates Google search engine results to perform SEO fraud, primarily benefiting gambling websites. Gamshen only alters responses to Googlebot requests, ensuring regular visitors are unaffected, but this tactic damages the reputation of compromised websites by associating them with fraudulent SEO practices. GhostRedirector also employs known exploits like BadPotato and EfsPotato to escalate privileges and create persistent, privileged user accounts. Their victims span multiple industries, including healthcare, education, insurance, transportation, retail, and technology, demonstrating no sector-specific targeting. ESET researchers have informed affected organizations and provided mitigation guidance, highlighting the group's operational resilience and sophisticated multi-faceted cybercrime approach.
Gamshen malware is typically installed in the directory C:\ProgramData\Microsoft\DRM\log\miniscreen.dll and registers a hardcoded URL to wait for specific incoming requests before executing commands.
GhostRedirector has been active since at least August 2024, with activity continuing through April 2025, and an internet scan in June 2025 revealed additional victims.
The group creates fake, privileged user accounts as a backup access method to maintain long-term presence even if other malware is discovered and removed.
Many compromised servers in the United States appear to be leased to companies based in Brazil, Thailand, and Vietnam, indicating a focus on targets in Latin America and Southeast Asia.
ESET researcher Fernando Tavella provided key explanations of the malware’s operation, emphasizing that while Gamshen does not affect normal visitors, it damages the reputation of the compromised websites through association with fraudulent SEO activities.
Publishers
10
Articles
4
Reach
14