GhostRedirector is a financially motivated cybercrime cluster active since at least August 2024 that compromises Windows servers running Microsoft Internet Information Services (IIS) for search engine optimization (SEO) fraud. In June 2025, its activity encompassed at least 65 compromised Windows servers, primarily in Brazil, Thailand, and Vietnam. The cluster deploys Rungan, a passive C++ backdoor, and Gamshen, a malicious native IIS module. Gamshen manipulates search-engine results to promote gambling websites and supports SEO fraud-as-a-service operations. GhostRedirector is tracked separately from other IIS-focused clusters, including DragonRank, Operation Rewrite, and UAT-8099; shared targeting and SEO-fraud objectives do not establish a common operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A China-aligned actor assessed by ESET that compromises Windows IIS servers and deploys the Gamshen native IIS module for gambling-related SEO fraud. Gamshen selectively changes responses for Googlebot while leaving ordinary visitors on the requested page.
Named China-linked operation previously observed targeting IIS servers.
China-aligned threat group observed targeting IIS web servers.
A financially motivated, China-linked cluster associated with SEO fraud against IIS servers. It is discussed as a comparison for OP-512's targeting and privilege-escalation techniques, rather than as a participant in the reported intrusion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.