Skip to content

Online gambling: hackers hijack Windows servers to boost illegal betting sites on Google

Tony Colapinto
Written by Tony Colapinto

A new cyber threat is shaking the online gambling industry. A group of hackers of Chinese origin has launched a global campaign aimed at exploiting vulnerable Windows servers to manipulate Google search results and promote unregulated betting platforms. The operation, identified by researchers at ESET, has been named GhostRedirector and has been active since at least December 2024.

A criminal network exploiting compromised servers

According to experts, at least 65 servers have been breached, with a concentration in Latin America and Southeast Asia. Brazil, Thailand and Vietnam are the most affected countries, although some cases have also been reported in the United States. The victims come from a wide range of sectors, including healthcare, education, transport, retail and insurance. This diversity shows that the attacks are not industry-specific but rather opportunistic, taking advantage of unpatched vulnerabilities.

Access to systems is mainly gained through neglected SQL flaws. Once control is established, the hackers deploy PowerShell scripts that download malicious tools, installing two new threats: Rungan and Gamshen.

Rungan and Gamshen: two complementary weapons

Rungan functions as a backdoor, providing continuous remote access to the compromised server. This ensures hackers can retain control over the system for the long term, even when other security measures are updated.

Even more insidious is Gamshen, a trojan embedded in Microsoft’s IIS web server. This module selectively manipulates the HTTP responses sent to Googlebot, Google’s indexing crawler. Hidden backlinks and SEO content are injected, visible only to the crawler, artificially boosting the search rankings of illegal gambling sites.

An invisible yet highly damaging attack

The technique employed by GhostRedirector is particularly deceptive because it does not alter the normal browsing experience of users. This makes the attack extremely difficult to detect. Operators of compromised sites, however, face serious consequences such as SEO penalties from Google or being flagged as suspicious websites.

Many administrators may not even notice the intrusion until they experience sudden and unexplained drops in their SEO rankings. The stealthy nature of the trojan is what makes the campaign so effective and damaging.

The ultimate goal of the hackers is clear: boosting the visibility of unlicensed online gambling platforms. These websites often operate from offshore jurisdictions, far from the oversight of national regulators. They bypass consumer protection frameworks and pose risks both to users and to operators that comply with the law.

The spread of unregulated gambling sites, amplified by such illegal SEO manipulation, undermines the legitimate market. It not only deprives governments of tax revenues but also exposes players to platforms that lack safety, fairness and transparency.

A global challenge for security and regulation

The rise of GhostRedirector highlights the urgent need for a coordinated response across different stakeholders: technology companies, gambling regulators and law enforcement agencies. Stricter monitoring of vulnerable web servers, regular system patching and increased awareness around digital security are essential measures to counter such campaigns.

The case also underscores how search engine dynamics can be manipulated in invisible yet disruptive ways. This should encourage regulators and digital providers to strengthen cooperation in order to protect legitimate operators from being overshadowed by criminal strategies.

An outlook that demands constant vigilance

The GhostRedirector operation represents a new frontier of cybercrime: rather than stealing data or money directly, it exploits Google’s indexing rules to entrench the ecosystem of illegal gambling. It is a stark reminder of how hackers adapt ingeniously to digital dynamics, turning search engines into unwitting tools for promoting clandestine activities.

The challenge for governments and businesses will be to anticipate such attacks and ensure that legitimate platforms are not drowned out by increasingly sophisticated criminal tactics.

This article was first published in Italian on 10 September 2025.

All roads lead to Rome, 03–06 November 2025. SiGMA Central Europe takes centre stage at the Fiera Roma, uniting 30,000 delegates, 1,200 exhibitors, and 700+ speakers. This is where legacies are built, and the future takes shape. Connect with the innovators’ driving change.

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.