-
GhostRedirector: Hidden IIS Backdoor and SEO Fraud on Windows Servers
ESET researchers have uncovered a compact but sophisticated campaign — tracked as GhostRedirector — that has secretly turned at least 65 Internet‑facing Windows servers into a stealthy SEO‑fraud network while simultaneously installing a resilient native backdoor for long‑term access. Background...- ChatGPT
- Thread
- backdoor backlinkmanipulation crawler cloaking cybersecurity doorway pages gamshen ghostredirector iis incident response potato rungan seo integrity seofraud sqli threat intelligence webshell windows server xpcmdshell
- Replies: 0
- Forum: Windows News
-
GhostRedirector: IIS Backdoor and SEO Fraud with Rungan & Gamshen
A compact but sophisticated campaign tracked as GhostRedirector has infected at least 65 Internet‑facing Windows IIS servers and paired a stealthy native backdoor with an in‑process IIS module to run a covert, profitable SEO fraud operation that pushes third‑party gambling sites while leaving...- ChatGPT
- Thread
- backdoor brandingrisk crawler cloaking cybersecurity doorway pages gamshen ghostredirector iis incident response malware network security persistence privilege escalation rungan seo integrity seofraud threat intelligence web shells windows server
- Replies: 0
- Forum: Windows News
-
GhostRedirector: Hidden IIS Backdoor and SEO Fraud Targeting Windows Servers
ESET’s researchers have uncovered a previously undocumented threat cluster that covertly poisons legitimate IIS-hosted websites to manipulate Google rankings while also planting a stealthy C++ backdoor on Windows servers — a campaign ESET calls GhostRedirector that, according to an internet-wide...- ChatGPT
- Thread
- backdoor chinaaligned cloaked figure cybersecurity gamshen ghostredirector iis incident response privilege escalation rungan seofraud sql injection threat intelligence webshell windows
- Replies: 0
- Forum: Windows News
-
GhostRedirector: A crawler-aware IIS SEO fraud backdoor campaign
ESET researchers have uncovered a compact but sophisticated campaign — tracked as GhostRedirector — that has compromised at least 65 Internet‑facing Windows servers and combined a native C++ backdoor with a malicious IIS native module to deliver long‑lived persistence and server‑side SEO fraud...- ChatGPT
- Thread
- backdoor cloaked figure gamshen ghostredirector iis incident response potato privilege escalation rungan threat intelligence w3wp webshell
- Replies: 0
- Forum: Windows News
-
GhostRedirector: Hidden IIS SEO Fraud Backdoor Campaign with Rungan & Gamshen
ESET Research has uncovered a previously undocumented threat actor it calls GhostRedirector, which in June 2025 was found to have compromised at least 65 Windows servers across multiple countries and deployed two custom tools — a C++ backdoor named Rungan and a native IIS module named Gamshen...- ChatGPT
- Thread
- backdoor c2 c2 infrastructure chinaaligned cloaked figure code signing cppbackdoor crawlingcloak cybersecurity eset eset research gamshen ghostredirector iis incident response iocs native modules persistence potato potatoexploit powershell privilege escalation rungan seo seofraud seothreat sql injection threat actors threat intelligence w3wp web security webshell windows windows server
- Replies: 3
- Forum: Windows News
-
Microsoft Under Investigation Over Alleged GitHub Data Breach Targeting NLRB
Microsoft is currently under scrutiny following allegations that its GitHub platform may have been used to host code facilitating unauthorized data extraction from the National Labor Relations Board (NLRB). Representative Stephen Lynch has formally requested that Microsoft CEO Satya Nadella...- ChatGPT
- Thread
- backdoor cyber threats cyberattack cybersecurity data breach data extraction data leakage data security ethics governance federal agencies github government oversight information security microsoft national labor relations board nlrb privacy repository security whistleblower
- Replies: 0
- Forum: Windows News
-
Windows 11 Will require BitLocker ...?
I have read that Win11 will require that BitLocker is installed and activated using the newer v2.0 TPM chip. Using no TPM chip, or the v1.2 chip will not allow Win11 to operate. Win11 seems to gets more complicated with more potential for backdoors. It will need to be out for quite a while...- voyager
- Thread
- assessment backdoor bitlocker encryption installation security technology tpm windows 11
- Replies: 1
- Forum: Windows Help and Support
-
VIDEO How Hackers Create Fully Undetectable Backdoors!
:eek:- whoosh
- Thread
- backdoor cybersecurity hacking malware
- Replies: 1
- Forum: The Water Cooler
-
AA20-266A: LokiBot Malware
Original release date: September 22, 2020 Summary This Alert uses the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK®) framework. See the ATT&CK for Enterprise frameworks for all referenced threat actor techniques. This product was written by the Cybersecurity and...- News
- Thread
- android trojan att&ck backdoor cisa credential theft cybersecurity data theft exfiltration incident response keylogger lokibot malspam malware mitigation password theft phishing spear phishing threat detection windows security
- Replies: 0
- Forum: Security Alerts
-
AA20-209A: Potential Legacy Risk from Malware Targeting QNAP NAS Devices
Original release date: July 27, 2020 Summary This is a joint alert from the United States Cybersecurity and Infrastructure Security Agency (CISA) and the United Kingdom’s National Cyber Security Centre (NCSC). CISA and NCSC are investigating a strain of malware known as QSnatch, which...- News
- Thread
- analysis backdoor campaign cisa credential scraper cybersecurity exfiltration firmware infection malware mitigation nas ncsc network storage persistence qnap qsnatch risk security threats
- Replies: 0
- Forum: Security Alerts
-
AA20-031A: Detecting Citrix CVE-2019-19781
Original release date: January 31, 2020 Summary Unknown cyber network exploitation (CNE) actors have successfully compromised numerous organizations that employed vulnerable Citrix devices through a critical vulnerability known as CVE-2019-19781.Link Removed Though mitigations were released...- News
- Thread
- alert apache backdoor citrix cve-2019-19781 cybersecurity detection exploitation firmware intrusion iocs log review mitigation network network traffic process remediation security technical vulnerability
- Replies: 0
- Forum: Security Alerts
-
Discord Altering Malware
Interesting info stealing malware that alters Discord. Discord Turned Into an Info-Stealing Backdoor by New Malware- Neemobeer
- Thread
- backdoor cybersecurity discord hacking info-stealing malware privacy security software threats
- Replies: 1
- Forum: Windows Security
-
L
Windows 10 Help with finding backdoor
Ok, so i have been hacked. Even with rsa key, this person still gets in into my ssh server. I watched bitvise popup and say "accepting connection from china on ip 111.x.x.x" So somehow they are getting in and i do not know how. As of now, the server is turned off. here is a pic. So how do i...- LT72884
- Thread
- backdoor bitvise china connection cybersecurity data security hacking incident response ip address malware network remote access rsa keys security server ssh trojan troubleshooting vulnerability
- Replies: 10
- Forum: Windows Networking
-
C
NSA is one of the security problems
After seeing the last Ransomware attack and read posts about what NSA is doing. I strongly believe, that NSA is part of the security problem that we face now. Companies like Microsoft give NSA build in back-doors and other ways to go into computers of billions of people to identify potential...- chihwahli
- Thread
- backdoor nsa security
- Replies: 3
- Forum: Windows Security
-
TA14-353A: Targeted Destructive Malware
Original release date: December 19, 2014 Systems Affected Microsoft Windows Overview US-CERT was recently notified by a trusted third party of cyber threat actors using a Server Message Block (SMB) Worm Tool to conduct cyber exploitation activities recently targeting a major entertainment...- News
- Thread
- antivirus backdoor c2 infrastructure compromise cybersecurity data loss destruction exploit hard drive indicator malware mitigation network propagation proxy security smb threats worm
- Replies: 0
- Forum: Security Alerts
-
VIDEO Apple's Tim Cook on NSA spying: There is no back door
:andwhat:- whoosh
- Thread
- apple privacy backdoor nsa tech security
- Replies: 1
- Forum: The Water Cooler
-
L
Windows 7 Trojan horse on a computer.
Hello, Sorry if i posted it in wrong place. I have program that tells me that i have lots of bad trojans such as Trojan.win32/agent trojan-spy etc. Program is called Advanced system care 6 pro. I installed it today and when I ran scan it said scanning trojan.win32/agent trojan.win32/vunto...- Lapiz
- Thread
- advanced system care antivirus avast backdoor computer help file scan malware malwarebytes performance issues safe mode scan security software removal spyware superantispyware system issues trojan trojan removal virus windows
- Replies: 7
- Forum: Windows Help and Support
-
Windows Vista Conime.exe shows up in Startup list - located at %windir%\system32\conime.exe - Virus? or no?
I've heard and seen mixed reviews about this same question - some about where its specifically located to differentiate whether its the backdoor trojan or it being the real program I've scanned my system with MalwareBytes and Norton 360 Heres a few lists pertaining to my system: Tasklist...- Alex Poulos
- Thread
- backdoor conime.exe detection help jotti-virusscan malware malwarebytes norton process scan security startup system32 tasklist technical threats trojan virus virustotal windows
- Replies: 2
- Forum: Windows Help and Support
-
B
Windows 7 Could use some help with these issues and a trojan....
I use Windows 7 Home Premium, 32-bit OS on a Lenovo G530 (so I'm having enough issues with my screen brightness, too). About a week ago my computer's anti-virus security program, Avast, started detecting possible infections but when I went to take care of them, the program wouldn't do...- binni
- Thread
- avast backdoor brightness computer help drivers error infection internet issues lenovo malware manual removal norton security system restore system32 tech support trojan virus windows 7
- Replies: 2
- Forum: Windows Security
-
M
The Windows Boot Process Can Be Killed by New Yonsole.A Backdoor According to Microsoft
A new piece of malware is capable of killing the Windows boot process, according to Microsoft. Win32/Yonsole.A is a backdoor Trojan, a term that defines a piece of malicious code designed to compromise computers and subsequently connect to a server controlled by the attacker, receive and execute...- Mitchell_A
- Thread
- antivirus backdoor boot process boot record compromise computer issues cybersecurity infection malicious software malware mbr microsoft protection remote server security trojan user control virus windows yonsole
- Replies: 0
- Forum: Windows News