None
EN
GhostRedirector poisons Windows servers: Backdoors with a side of Potatoes
[]
WeLiveSecurity
ESET researchers have identified a new threat actor, whom we have named GhostRedirector, that compromised at least 65 Windows servers mainly in Brazil, Thailand, and Vietnam.
GhostRedirector has an arsenal that includes the passive C++ backdoor Rungan, the malicious IIS trojan Gamshen, and a variety of other utilities.
GhostRedirector is not the first known case of a China-aligned threat actor engaging in SEO fraud via malicious IIS modules.
Note the ExeHelper class, which provides a function to execute a file named link.exe – GhostRedirector used the same filename to deploy the GoToHTTP tool.
Table 3.Rungan backdoors commandsParameter Body Description Response mkuser user=<USERNAME>&pwd=<PASSWORD>&groupname=<GROUPNAME> Creates the specified user on the compromised server using the NetUserAdd Windows API.
['potatoes'
'backdoors'
'used'
'compromised'
'iis'
'servers'
'poisons'
'seo'
'ghostredirector'
'user'
'backdoor'
'server'
'gamshen'
'malicious'
'windows']