Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GhostRedirector

Also known as: tracked as, Googlebot, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, BokBot, UNC2596, Scattered Spider

Description

GhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily in Brazil, Thailand, and Vietnam. It employs a passive C++ backdoor named Rungan and a malicious IIS module called Gamshen to maintain persistent access and manipulate search engine results for SEO fraud. The actor utilizes public exploits like EfsPotato and BadPotato for privilege escalation and abuses code-signing certificates to evade detection. GhostRedirector's operations involve installing remote access tools, creating rogue administrator accounts, and leveraging SQL injection vulnerabilities to execute PowerShell for downloading malicious payloads.

Goals & Targeting

Targeted Sectors

Telecommunications
Financial services
Manufacturing
Defense
Transportation
Healthcare
Education
Retail
Government
Aerospace
Critical infrastructure
Aviation
Energy
Oil gas
Food agriculture
Construction
Media
Mining
Entertainment
Non profit
Gaming
Legal services
Utilities
Hospitality

Targeted Countries / Regions

US
CN
BR
VN
RU
SG
CA
BY
IN
NL
KZ
TW
TR
JP
GB
AU
EG

AI Analysis

· 1 week ago

Executive Summary

GhostRedirector, a suspected China-aligned threat actor, has targeted at least 65 Windows servers across Brazil, Thailand, and Vietnam. The group uses custom backdoors and malicious IIS modules to gain persistent access for SEO fraud and financial gain. Their operations include exploiting vulnerabilities like EfsPotato and BadPotato, using code-signing certificates for evasion, and deploying remote access tools.

Goals & Targeting

GhostRedirector's primary objective appears to be economic gain through fraudulent activities, particularly SEO fraud, by manipulating search engine results. The targeting of servers in Brazil, Thailand, and Vietnam suggests a focus on regions where such operations might yield higher financial returns. The group’s modus operandi focuses on compromising sectors where server infrastructure is less secure or where the impact of SEO manipulation has significant economic implications.

Enhanced Description

GhostRedirector is a sophisticated threat actor attributed to China, known for compromising Windows servers in Brazil, Thailand, and Vietnam. The group utilizes a C++ backdoor named Rungan and a malicious IIS module called Gamshen to maintain persistence and manipulate search engine results, likely for SEO fraud purposes. GhostRedirector employs public exploits such as EfsPotato and BadPotato for privilege escalation and abuses code-signing certificates to evade detection. The actor's operations involve installing remote access tools, creating rogue administrator accounts, and leveraging SQL injection vulnerabilities to execute PowerShell commands for downloading malicious payloads.

Key Capabilities

  • Custom backdoors (Rungan)
  • Malicious IIS modules (Gamshen)
  • Public exploit tools (EfsPotato, BadPotato)
  • Code-signing certificate abuse
  • SQL injection attacks
  • Remote access tool deployment
  • Credential dumping
  • Persistence mechanisms

MITRE ATT&CK Tactics

Initial Access
Exploitation for Privilege Escalation
Defense Evasion
Persistence

ATT&CK Techniques

T1059.003
T1055
T1566.002
T1566.004
T1003.001

Software / Tooling

Rungan backdoor
Gamshen IIS module
EfsPotato exploit
BadPotato exploit
Code-signing certificates

Campaigns & Victims

GhostRedirector has been active since at least 2016, targeting servers across Brazil, Thailand, and Vietnam. The group appears to focus on long-term access for financial gain through SEO fraud rather than traditional APT-style data exfiltration. Their campaigns involve a mix of custom tools and existing exploits to compromise victim systems. Notable operations include the consistent use of remote access tools and SQL injection attacks to download malicious payloads.

IOC Patterns

  • Malicious IIS module file paths
  • Specific backdoor filenames (e.g., Rungan.exe)
  • Code-signed binaries from known certificate authorities
  • SQL injection attempts targeting MS-SQL databases
  • Unusual network traffic patterns to known infrastructure

Recommended Actions

  • Patch and mitigate known vulnerabilities like EfsPotato and BadPotato.
  • Monitor IIS server logs for suspicious activity.
  • Use tools like Tripwire to detect unauthorized file changes.
  • Limit administrative access to servers.
  • Educate users about phishing and social engineering attempts.

Suggested Tags

APT30
RedLeaf
cyber_espionage
financial_fraud
south_east_asia
south_east asian_operations

Confidence Assessment

Moderate confidence in GhostRedirector's China-alignment and targeting patterns, based on OSINT analysis and TTP comparison. Some gaps remain regarding exact campaign links and complete timeline data.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 12 MD5 Hash 1 Filename 5 SHA-1 Hash 2

References

  1. www.welivesecurity.com — Cited by web research for: Googlebot
  2. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  3. research.checkpoint.com — Cited by web research for: phishing
  4. www.eset.com — Cited by web research for: Singapore

Intel Summary

26

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

9

Tactics

Tags

APT
Backdoor / C2
APT30
RedLeaf
cyber_espionage
financial_fraud
south_east_asia
south_east asian_operations

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.