Also known as: tracked as, Googlebot, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, BokBot, UNC2596, Scattered Spider
GhostRedirector is a China-aligned threat actor that has compromised at least 65 Windows servers across various sectors, primarily in Brazil, Thailand, and Vietnam. It employs a passive C++ backdoor named Rungan and a malicious IIS module called Gamshen to maintain persistent access and manipulate search engine results for SEO fraud. The actor utilizes public exploits like EfsPotato and BadPotato for privilege escalation and abuses code-signing certificates to evade detection. GhostRedirector's operations involve installing remote access tools, creating rogue administrator accounts, and leveraging SQL injection vulnerabilities to execute PowerShell for downloading malicious payloads.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
GhostRedirector, a suspected China-aligned threat actor, has targeted at least 65 Windows servers across Brazil, Thailand, and Vietnam. The group uses custom backdoors and malicious IIS modules to gain persistent access for SEO fraud and financial gain. Their operations include exploiting vulnerabilities like EfsPotato and BadPotato, using code-signing certificates for evasion, and deploying remote access tools.
Goals & Targeting
GhostRedirector's primary objective appears to be economic gain through fraudulent activities, particularly SEO fraud, by manipulating search engine results. The targeting of servers in Brazil, Thailand, and Vietnam suggests a focus on regions where such operations might yield higher financial returns. The group’s modus operandi focuses on compromising sectors where server infrastructure is less secure or where the impact of SEO manipulation has significant economic implications.
Enhanced Description
GhostRedirector is a sophisticated threat actor attributed to China, known for compromising Windows servers in Brazil, Thailand, and Vietnam. The group utilizes a C++ backdoor named Rungan and a malicious IIS module called Gamshen to maintain persistence and manipulate search engine results, likely for SEO fraud purposes. GhostRedirector employs public exploits such as EfsPotato and BadPotato for privilege escalation and abuses code-signing certificates to evade detection. The actor's operations involve installing remote access tools, creating rogue administrator accounts, and leveraging SQL injection vulnerabilities to execute PowerShell commands for downloading malicious payloads.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
GhostRedirector has been active since at least 2016, targeting servers across Brazil, Thailand, and Vietnam. The group appears to focus on long-term access for financial gain through SEO fraud rather than traditional APT-style data exfiltration. Their campaigns involve a mix of custom tools and existing exploits to compromise victim systems. Notable operations include the consistent use of remote access tools and SQL injection attacks to download malicious payloads.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Moderate confidence in GhostRedirector's China-alignment and targeting patterns, based on OSINT analysis and TTP comparison. Some gaps remain regarding exact campaign links and complete timeline data.
No campaigns linked yet.
No observed data linked yet.
26
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
9
Tactics