GhostRedirector: China-Aligned Threat Actor Manipulates SEO for Gambling Sites

ESET Research uncovers GhostRedirector, a China-aligned threat actor using custom backdoors and an IIS module to manipulate SEO for illicit gambling websites. The group compromises Windows servers globally, redirecting traffic and causing reputational damage to legitimate organizations.

A stylized black hand places a document with text and blue blocks onto a network of interconnected nodes. Some nodes are simple circles, while others are complex, multi-faceted black geometric shapes.
Illustration by Addison Smith for Success Quarterly
Share:

In the ever-shifting landscape of global cyber warfare, a new and unsettling player has emerged, pulling digital puppet strings from the shadowy corners of the internet.

ESET Research has peeled back the layers on a previously unknown, China-aligned threat actor, christened GhostRedirector, revealing a sophisticated operation that blends traditional backdoor tactics with an insidious twist: the manipulation of search engine results to promote illicit gambling ventures.

The discovery, detailed by ESET researchers, paints a picture of a well-resourced and persistent adversary.

In June 2025, an internet-wide scan identified at least 65 Windows servers compromised by GhostRedirector, with victims spanning the globe from Brazil, Thailand, and Vietnam to the United States, Canada, Finland, India, and beyond.

While the geographic spread appears wide, ESET’s deep dive suggests a particular interest in Latin America and Southeast Asia, even when leveraging servers physically located in the United States but leased by companies based in the primary target regions.

GhostRedirector’s toolkit is a testament to its ingenuity and determination.

Central to its operations are two custom-built, previously undocumented malicious components: Rungan, a passive C++ backdoor, and Gamshen, a malicious Internet Information Services (IIS) module.

Rungan provides the attackers with a robust foothold, granting capabilities for command execution, network communication, file manipulation, and control over Windows services and registry keys – essentially, full command of the compromised server.

However, it is Gamshen that truly sets GhostRedirector apart, revealing a strategic pivot into the murky waters of SEO fraud-as-a-service.

This module’s purpose is deceptively simple yet profoundly impactful: to manipulate Google search engine results, artificially boosting the page rankings of configured target websites, predominantly those associated with online gambling.

As ESET researcher Fernando Tavella, who spearheaded the discovery, explains, “Even though Gamshen only modifies the response when the request comes from Googlebot — i.e., it does not serve malicious content or otherwise affect regular visitors of the websites — participation in the SEO fraud scheme can hurt the compromised host website’s reputation by associating it with shady SEO techniques, as well as with the boosted websites.”

This nuanced approach to exploitation highlights a growing trend in cyber malfeasance.

It’s no longer solely about outright data theft or system destruction.

Here, the objective is subtler, leveraging the very mechanisms designed to help users find information to instead funnel them towards potentially harmful or unregulated content.

The reputational damage to the compromised organizations, whose legitimate websites unwittingly become conduits for this digital deception, is a silent but significant casualty.

It erodes trust, not just in the individual site, but in the broader digital ecosystem and the integrity of search results.

Beyond Rungan and Gamshen, GhostRedirector demonstrates a comprehensive approach to maintaining persistent access.

The group deploys a suite of other custom tools, alongside publicly known exploits like EfsPotato and BadPotato (colloquially referred to as “potatoes” in the cybersecurity community), to escalate privileges and create rogue user accounts.

These measures serve a dual purpose: ensuring long-term access to the compromised infrastructure and acting as crucial fallback mechanisms should their primary backdoors be detected and removed.

This multi-layered strategy underscores an operational resilience that speaks volumes about the group’s resources and commitment.

The initial access vector for GhostRedirector is believed to be SQL Injection vulnerabilities, a common but often devastating flaw that allows attackers to inject malicious code into a server’s database.

Once inside, the attackers move swiftly to deploy their arsenal, including privilege escalation tools, various webshells for remote access, and, of course, Rungan and Gamshen.

This methodical approach, from initial breach to establishing deep-rooted persistence and specialized fraud operations, points to a highly organized and professional outfit.

GhostRedirector’s victimology is as varied as its methods.

ESET’s telemetry shows no specific industry vertical was targeted; instead, victims span a wide array of sectors, including education, healthcare, insurance, transportation, technology, and retail.

This opportunistic targeting suggests a focus on vulnerable Windows servers rather than specific high-value data, aligning with the SEO fraud objective.

The attacks, first detected between December 2024 and April 2025, signify a sustained campaign of compromise.

The emergence of GhostRedirector serves as a stark reminder of the evolving threat landscape.

When a seemingly innocuous act like boosting gambling websites is facilitated by a sophisticated, China-aligned threat actor employing custom backdoors and exploiting critical vulnerabilities, it underscores the complex interplay between state-sponsored capabilities and financially motivated cybercrime.

ESET’s swift identification and notification of victims, along with their detailed technical breakdown, provide crucial insights into this new adversary.

As the digital world continues to expand, so too does the ingenuity of those seeking to exploit it, demanding constant vigilance and a proactive defense against threats that are as varied as they are insidious.

Tags:
china, cybersecurity, malware, news, seofraud, threatactor
Join Our Newsletter
Stay up to date on latest stories
Join Our Newsletter
Stay up to date on latest stories
Copyright © 2026 Success Quarterly. All Rights Reserved.
Copyright © 2024 Success Quarterly. All Rights Reserved.
Join our newsletter
Stay up to date on latest stories
Close