GhostRedirector is a China-linked threat cluster active since at least August 2024 that compromises Microsoft Internet Information Services (IIS) servers on Windows to conduct SEO fraud. The actor has been observed compromising at least 65 Windows servers, with activity concentrated in Brazil, Thailand, and Vietnam. GhostRedirector deploys a passive C++ backdoor known as Rungan together with a malicious IIS module called Gamshen. Gamshen manipulates web traffic and search-engine results to support SEO fraud, and has been assessed as enabling SEO-fraud-as-a-service. GhostRedirector is part of a broader ecosystem of China-linked or Chinese-speaking operations abusing IIS infrastructure, but available reporting treats it as a distinct cluster rather than the same operator as DragonRank, Operation Rewrite, or UAT-8099/WEBJACK. The actor’s known tradecraft supports persistent compromise of web servers and post-compromise traffic manipulation rather than ransomware or destructive operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named China-linked operation previously observed targeting IIS servers.
China-aligned threat group observed targeting IIS web servers.
Cluster compromising Windows servers (noted in Brazil/Thailand/Vietnam) deploying Rungan backdoor and Gamshen IIS module for persistence/traffic manipulation.
Separate IIS SEO-fraud/redirector activity cluster in the same problem space; treated as low-probability match to UAT-8099/WEBJACK unless specific GhostRedirector hallmarks (e.g., Rungan/Gamshen artifacts and associated domains) are present.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.