GhostRedirector Hackers Target Windows Servers Using Malicious IIS Module
Security researchers at ESET have identified a sophisticated cyber threat campaign targeting Windows servers globally. This campaign involves custom malware tools designed for remote access and search engine manipulation.
Security researchers at ESET have identified a sophisticated cyber threat campaign targeting Windows servers globally. This campaign involves custom malware tools designed for remote access and search engine manipulation.
The threat group, named GhostRedirector, has compromised at least 65 Windows servers, primarily in Brazil, Thailand, and Vietnam. The attacks, first detected in December 2024, utilize traditional server compromise techniques alongside innovative search engine optimization fraud.
Rungan: A passive C++ backdoor enabling remote command execution. It is typically installed in C:\ProgramData\Microsoft\DRM\log\miniscreen.dll and registers a hardcoded URL for executing commands on compromised systems. Gamshen: An IIS module designed to alter server responses to Google's web crawler, Googlebot. It injects fraudulent content aimed at boosting the search engine rankings of specific websites, primarily targeting Portuguese-speaking users.
These tools enable attackers to manipulate legitimate websites' authority, benefiting clients through increased page rankings.
GhostRedirector gains initial access via SQL injection vulnerabilities, using PowerShell to download additional tools from 868id[.]com . The group employs multiple persistence mechanisms and utilizes publicly available exploits, such as EfsPotato and BadPotato, for privilege escalation. This includes creating administrative user accounts on compromised servers.
Security researchers at ESET have identified a sophisticated cyber threat campaign targeting Windows servers globally.
The campaign affects servers across multiple continents, with notable concentrations in South America and Southeast Asia. Victims span various industries, including healthcare, education, insurance, transportation, technology, and retail. Additional compromised systems have been identified in Canada, Finland, India, the Netherlands, the Philippines, and Singapore.
Security researchers suggest a potential alignment with China, based on several indicators, including code-signing certificates and language strings in malware samples.
This campaign highlights the intersection of server compromise techniques with search engine manipulation for financial gain. The use of legitimate website authority to promote fraudulent content poses significant risks to compromised organizations and internet users.
ESET has notified affected parties and continues to monitor the threat group’s activities. The research emphasizes the importance of maintaining updated server security measures and monitoring for unusual network activity, particularly unauthorized PowerShell executions.
The GhostRedirector campaign exemplifies modern cybercriminals' use of multiple attack vectors to maximize persistence and profit, necessitating comprehensive security strategies for effective detection and mitigation.
Based on reporting by GBHackers.
