Rungan is a passive C++ backdoor associated with intrusion activity involving IIS-based server compromise. It has been tracked alongside GhostRedirector IIS module abuse and is linked to post-exploitation on Windows web infrastructure, particularly scenarios involving public-facing application compromise and suspicious child-process execution from web server processes. The malware is characterized in available reporting as a backdoor rather than a commodity loader or infostealer.
Operational context ties Rungan to server-side intrusion chains in which attackers abuse web-facing services and IIS components to establish covert access and maintain control after initial compromise. Detection associations place it in environments involving web shell-like behavior, IIS module persistence, SQL Server abuse, remote access software usage, suspicious PowerShell activity, and privilege-escalation patterns, indicating use in broader hands-on-keyboard post-compromise operations rather than mass malware distribution.
High-confidence public facts in the available material support Windows as the relevant platform and support classification as a backdoor. Specific delivery vectors, victimology, and actor attribution are not established with sufficient confidence from the available information. Likewise, concrete capabilities beyond maintaining unauthorized access are not directly described in the available facts and should be treated as currently not available.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
... led to the deployment of a passive C++ backdoor called Rungan ...
Detect Exchange Web Shell ... BlackByte Ransomware, Seashell Blizzard, GhostRedirector IIS Module and Rungan Backdoor
Detect Exchange Web Shell ... BlackByte Ransomware, Seashell Blizzard, GhostRedirector IIS Module and Rungan Backdoor
Detect Exchange Web Shell ... BlackByte Ransomware, Seashell Blizzard, GhostRedirector IIS Module and Rungan Backdoor
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor malware family referenced in an associated analytic story title involving IIS compromise.
Backdoor referenced in an associated analytic story.
Rungan is referenced as a backdoor in an associated analytic story.
Associated Analytic Story ... GhostRedirector IIS Module and Rungan Backdoor
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.