Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

GhostRedirector Hackers Target Windows Servers Using Malicious IIS Module

Security researchers at ESET have identified a sophisticated cyber threat campaign targeting Windows servers globally. This campaign involves custom malware tools designed for remote access and search engine manipulation.

Security researchers at ESET have identified a sophisticated cyber threat campaign targeting Windows servers globally. This campaign involves custom malware tools designed for remote access and search engine manipulation.

The threat group, named GhostRedirector, has compromised at least 65 Windows servers, primarily in Brazil, Thailand, and Vietnam. The attacks, first detected in December 2024, utilize traditional server compromise techniques alongside innovative search engine optimization fraud.

Rungan: A passive C++ backdoor enabling remote command execution. It is typically installed in C:\ProgramData\Microsoft\DRM\log\miniscreen.dll and registers a hardcoded URL for executing commands on compromised systems. Gamshen: An IIS module designed to alter server responses to Google's web crawler, Googlebot. It injects fraudulent content aimed at boosting the search engine rankings of specific websites, primarily targeting Portuguese-speaking users.

These tools enable attackers to manipulate legitimate websites' authority, benefiting clients through increased page rankings.

GhostRedirector gains initial access via SQL injection vulnerabilities, using PowerShell to download additional tools from 868id[.]com . The group employs multiple persistence mechanisms and utilizes publicly available exploits, such as EfsPotato and BadPotato, for privilege escalation. This includes creating administrative user accounts on compromised servers.

Security researchers at ESET have identified a sophisticated cyber threat campaign targeting Windows servers globally.
Lucas Gallagher · Thehackingpost

The campaign affects servers across multiple continents, with notable concentrations in South America and Southeast Asia. Victims span various industries, including healthcare, education, insurance, transportation, technology, and retail. Additional compromised systems have been identified in Canada, Finland, India, the Netherlands, the Philippines, and Singapore.

Security researchers suggest a potential alignment with China, based on several indicators, including code-signing certificates and language strings in malware samples.

This campaign highlights the intersection of server compromise techniques with search engine manipulation for financial gain. The use of legitimate website authority to promote fraudulent content poses significant risks to compromised organizations and internet users.

Advertisement

ESET has notified affected parties and continues to monitor the threat group’s activities. The research emphasizes the importance of maintaining updated server security measures and monitoring for unusual network activity, particularly unauthorized PowerShell executions.

The GhostRedirector campaign exemplifies modern cybercriminals' use of multiple attack vectors to maximize persistence and profit, necessitating comprehensive security strategies for effective detection and mitigation.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories