GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module
Researchers studying cybersecurity have uncovered GhostRedirector, a hitherto unknown threat cluster that has compromised at least 65 Windows servers, mostly in Brazil, Thailand, and Vietnam.
A native Internet Information Services (IIS) module codenamed Gamshen and a passive C++ backdoor named Rungan were deployed as a result of the attacks, according to Slovak cybersecurity firm ESET. Since at least August 2024, the threat actor is thought to have been operating.
In a report shared with The Hacker News, ESET researcher Fernando Tavella stated that while Rungan is capable of carrying out commands on a compromised server, Gamshen's goal is to offer SEO fraud as-a-service, which is to manipulate search engine results in order to increase the page ranking of a configured target website...

