GhostRedirector Hacks 65 Windows Servers Using Rungan Backdoor and Gamshen IIS Module
GhostRedirector compromises Windows servers to deploy Rungan backdoor and Gamshen IIS module, enabling SEO fraud by manipulating Googlebot responses and executing commands via SQL injection.
GhostRedirector: Chinese hackers plague Windows servers
GhostRedirector, a Chinese hacker group, compromised at least 65 Windows servers using custom backdoors, public privilege exploits, fake accounts, and SEO-manipulating IIS modules.