Gamshen is a malicious native Microsoft Internet Information Services (IIS) module developed and deployed by the GhostRedirector threat actor on compromised Windows web servers. It performs search-engine optimization (SEO) fraud by manipulating search results to artificially promote gambling websites. Its role is website-ranking manipulation rather than the remote-access functionality provided by GhostRedirector’s separate Rungan backdoor.
Gamshen was deployed in a GhostRedirector campaign that compromised at least 65 Windows servers, primarily in Brazil, Thailand, and Vietnam. The actor, active since at least August 2024, used Gamshen alongside Rungan as part of its server-compromise operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The comparison table lists GhostRedirector's custom implants as “Yes (Rungan, Gamshen).”
2 distinct techniques documented for this family, organized by ATT&CK tactic.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malicious native IIS module used by GhostRedirector for SEO fraud, selectively modifying responses for Googlebot to promote gambling sites.
A custom implant associated with GhostRedirector, mentioned as background rather than as tooling observed in the OP-512 intrusion. Its functionality is not described.
Native IIS module used in GhostRedirector compromises; likely for traffic manipulation/redirect behavior (implied by context); no further details in excerpt.
Named tooling/artifact associated with GhostRedirector activity; used as a differentiator from UAT-8099/WEBJACK-style activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.