GhostRedirector: A New China-Aligned Threat Targeting Windows Servers for SEO Fraud

1 min read
Source: The Hacker News
GhostRedirector: A New China-Aligned Threat Targeting Windows Servers for SEO Fraud
Photo: The Hacker News
TL;DR

Cybersecurity researchers uncovered GhostRedirector, a threat group targeting at least 65 Windows servers mainly in Brazil, Thailand, and Vietnam, using a passive backdoor called Rungan and an IIS module named Gamshen to conduct SEO fraud and maintain long-term access, with suspected links to China.

Share this article

Want the full story? Read the original reporting

Read on The Hacker News