GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes
Sept. 8, 2025, 9:29 a.m.
Description
ESET researchers have identified a new threat actor named GhostRedirector that has compromised at least 65 Windows servers, primarily in Brazil, Thailand, and Vietnam. The actor utilizes two previously undocumented tools: a passive C++ backdoor called Rungan and a malicious Internet Information Services (IIS) module named Gamshen. While Rungan can execute commands on compromised servers, Gamshen's purpose is to manipulate search engine results, boosting the page ranking of configured target websites. The attacks appear to be opportunistic rather than targeting specific entities. GhostRedirector also employs public exploits like EfsPotato and BadPotato for privilege escalation. Based on various factors, including the use of Chinese strings and a Chinese code-signing certificate, ESET believes with medium confidence that GhostRedirector is a China-aligned threat actor.
Tags
Date
- Created: Sept. 8, 2025, 7:31 a.m.
- Published: Sept. 8, 2025, 7:31 a.m.
- Modified: Sept. 8, 2025, 9:29 a.m.
Indicators
- 7ddfcdf2429fffcdd283da11fc554aef06e5087ed21cb806cffb9f9af82d227d
- 27695e829f981e50c231a5d2a890d404b397f51103e84458a611b2625eb146bb
- 43.228.126.4
- 104.233.192.1
- 104.233.210.229
- 103.251.112.11
- www.cs01.shop
- www.881vn.com
- https://xzs.868id.com/link.exe
- https://xzs.868id.com/iis/br/ManagedEngine64_v2.dll
- https://xzs.868id.com/iis/IISAgentDLL.dll
- https://www.cs01.shop
- https://xzs.868id.com/EfsNetAutoUser_br.exe
- https://brproxy.868id.com/url/index_base64.php
- https://brproxy.868id.com/tz_base64.php
- https://brproxy.868id.com/index_base64.php
- http://xz.868id.com/EfsPotato_sign.exe
- http://gobr.868id.com/tz.php
- xzs.868id.com
- xz.868id.com
- q.822th.com
- gobr.868id.com
- brproxy.868id.com
- 868id.com
Attack Patterns
- Comdai
- Zunput
- Gamshen
- Rungan
- GhostRedirector
Additional Informations
- Retail
- Technology
- Insurance
- Healthcare
- Transportation
- Education
- British Indian Ocean Territory
- Finland
- Singapore
- India
- Netherlands
- Thailand
- Canada
- Philippines
- Brazil
- United States of America