ESET researchers have identified a new threat actor, whom we have named GhostRedirector, that compromised at least 65 Windows servers mainly in Brazil, Thailand, and Vietnam. GhostRedirector has an arsenal that includes the passive C++ backdoor Rungan, the malicious IIS trojan Gamshen, and a variety of other utilities. GhostRedirector is not the first known case of a China-aligned threat actor engaging in SEO fraud via malicious IIS modules. Note the ExeHelper class, which provides a function to execute a file named link.exe – GhostRedirector used the same filename to deploy the GoToHTTP tool. Table 3.Rungan backdoors commandsParameter Body Description Response mkuser user=<USERNAME>&pwd=<PASSWORD>&groupname=<GROUPNAME> Creates the specified user on the compromised server using the NetUserAdd Windows API.