GhostRedirector: A New China-Aligned Threat Targeting Windows Servers

1 min read
Source: WeLiveSecurity
GhostRedirector: A New China-Aligned Threat Targeting Windows Servers
Photo: WeLiveSecurity
TL;DR

ESET researchers uncovered GhostRedirector, a China-aligned threat actor that compromised at least 65 Windows servers mainly in Brazil, Thailand, and Vietnam, using custom tools like the passive backdoor Rungan and the malicious IIS module Gamshen to facilitate SEO fraud and maintain persistent access, with activities dating back to at least August 2024.

Share this article

Want the full story? Read the original reporting

Read on WeLiveSecurity