A new hacking group, dubbed “GhostRedirector,” has compromised at least 65 Windows servers worldwide, developing custom malware designed to manipulate search engine results for financial gain.

According to a report by ESET, attackers are using a malicious module for Microsoft's Internet Information Services (IIS) to conduct a sophisticated SEO scam , primarily benefiting gambling websites.
The attacks, active since at least August 2024, use two previously unknown custom tools: a passive C++ backdoor named “Rungan” and a malicious native IIS module called “Gamshen.”
See also: Stealerium malware targets educational institutions
Researchers explain that Gamshen interferes with web traffic on the infected server. The module is specially configured to activate only when it detects a request from Google's web crawler, Googlebot. For normal visitors, the website functions normally. However, when Googlebot crawls the site, Gamshen modifies the server's response, injecting data from its own command-and-control server. This technique allows attackers to create artificial backlinks and use other SEO tactics, essentially hijacking the reputation of the compromised site to boost the ranking of the target page.
ESET believes that the main beneficiaries of this scheme are various gambling websites that target Portuguese-speaking users. ESET researchers believe that this campaign may be linked to Chinese hackers. This assessment is based on several factors: use of a code-signing certificate issued to a Chinese company, hardcoded Chinese language strings within the malware samples , and a password containing the Chinese word “huang” (yellow), which is used for fake user accounts.
GhostRedirector: Where hackers are targeting
The attacks indicate that this is not a targeted campaign against a specific industry. The compromised servers are related to sectors such as healthcare, retail, transportation, education and technology, with the majority located in Brazil, Thailand and Vietnam. Additional victims were identified in the United States, Peru, Canada and parts of Europe and Asia.

See also: XWorm: New Infection and Detection Evasion Techniques
The GhostRedirector attack chain begins with what is believed to be an SQL injection vulnerability. Once inside, the attackers use PowerShell or CertUtil to download their weapons from a staging server. To gain full control, they use well-known privilege escalation exploits, such as “EfsPotato” and “BadPotato.” They then create new user accounts administrator-level on the server. These fake accounts provide persistent access, ensuring that the attackers can maintain control even if their primary backdoors are discovered and removed.
The group’s toolkit also includes other custom utilities, such as “Zunput“, a tool that scans the server for active websites and installs multiple webshells to provide alternative methods of remote access. The shared code libraries and infrastructure in these tools allowed ESET to group the activity and attribute it to a single group. While the direct impact on website visitors is minimal, engaging in SEO fraud can seriously damage the compromised host’s reputation by linking it to black-hat SEO tactics.
See also: Grok: Hackers abuse X's AI assistant

The GhostRedirector case once again reveals how cybercrime exploits the “gray zone” of the internet, where technology meets fraud. Although end users are not directly exposed to malware, the credibility and reputation of compromised organizations are drastically affected. Companies in critical industries, such as healthcare or transportation, are unwittingly caught up in black-hat SEO schemes, which can lead to loss of trust and penalties from search engines. GhostRedirector shows that hackers are not only targeting data, but also an organization’s “digital reputation.”
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
