- Casino
- By State
- Alabama
- Alaska
- Arizona
- Arkansas
- California
- Colorado
- Connecticut
- Delaware
- Georgia
- Florida
- Hawaii
- Idaho
- Illinois
- Indiana
- Iowa
- Kansas
- Kentucky
- Louisiana
- Maine
- Massachusetts
- Maryland
- Michigan
- Minnesota
- Mississippi
- Missouri
- Montana
- Nebraska
- Nevada
- New Hampshire
- New Jersey
- New Mexico
- New York
- North Carolina
- North Dakota
- Ohio
- Oklahoma
- Oregon
- Pennsylvania
- Rhode Island
- South Carolina
- South Dakota
- Tennessee
- Texas
- Utah
- Vermont
- Virginia
- Washington
- West Virginia
- Wisconsin
- Wyoming
- By State
- Slots
- Poker
- Sports
- Esports
Fact-checked by Angel Hristov
Illegal Gambling Operators Turn to Cyber Hacks to Climb Google Rankings
Recent research revealed how unregulated gambling platforms often resort to underhanded means to reach as many consumers as possible
The battle against unlicensed gambling has taken a new twist with the discovery of GhostRedirector, a China-linked hacking group using sophisticated malware to bolster the online presence of offshore betting sites. Cybersecurity company ESET Research drew attention to this threat in a new report, warning that this new breed of cybercrime and gambling fraud could have potentially global consequences.
The New Exploit Manipulates Google Search Results
ESET revealed that GhostRedirector infected at least 65 Windows servers between December 2024 and June 2025. While most victims were located in Brazil, Thailand, and Vietnam, the company also unveiled isolated cases in the United States, Canada, India, the Netherlands, Finland, and Singapore. Curiously, the group has targeted education, healthcare, transportation, technology, and retail rather than focusing on a single field.
The observed patterns indicate that GhostRedirector’s primary motive was not espionage but rather gaining access to vast amounts of web traffic. The mechanics, while straightforward, are shockingly effective. After gaining access to systems, often through SQL injection vulnerabilities, attackers deploy two custom programs: Rungan, a backdoor that runs commands on the compromised machines, and Gamshen, a malicious IIS module that tampers with search engines.
Unlike ransomware or phishing attacks, Gamshen does not aim to fool regular users. Instead, it modifies the content shown to Google’s web crawler. GhostRedirector utilizes this mode of attack to bolster the ranking of select gambling websites, artificially elevating them higher in search results and exposing unsuspecting users to unregulated platforms.
The Malicious Software Is Resilient and Difficult to Detect
Although regular users will likely never notice the injected code, the fact that the company’s domain becomes a vehicle for illegal gambling undermines their credibility and could result in blacklisting. ESET researcher Fernando Tavella, who made the discovery, noted that the malware cleverly avoids tipping off regular visitors to the affected websites, making it significantly more challenging to detect.
Gamshen only modifies the response when the request comes from Googlebot. It does not serve malicious content or otherwise affect regular visitors to the websites.
Fernando Tavella, ESET researcher
The group’s arsenal extends beyond Gamshen. Tools like EfsPotato and BadPotato allow attackers to escalate privileges, while rogue administrator accounts ensure long-term control. According to Tavella, GhostRedirector boasts impressive persistence layering itself across multiple access points so that purging one may not entirely eject the hackers, allowing them to continue using compromised infrastructure as springboards.
This new threat mirrors a similar cyberattack discovered in March, when a JavaScript hijack spread across thousands of legitimate websites worldwide. The attack redirected visitors to Chinese gambling portals, sometimes dressed up with branding from well-known operators like bet365. The link between the two episodes is clear, as operators who cannot get licensed in regulated markets resort to black-hat tactics to achieve visibility.
Related Topics:
Deyan is an experienced writer, analyst, and seeker of forbidden lore. He has approximate knowledge about many things, which he is always willing to apply when researching and preparing his articles. With a degree in Copy-editing and Proofreading, Deyan is able to ensure that his work writing for Gambling News is always up to scratch.
Previous Article
Industry
September 8, 2025
Scotland Advances Greyhound Racing Ban, to the Industry’s Dismay
Must Read
Industry
October 17, 2025
iGaming Discussions in Virginia Continue as Bill Is Put on Hold
Industry
October 17, 2025
KSA to Issue Partial Tax Refunds to Operators Affected by COVID
More Articles
Casino
October 23, 2025
Westmoreland Judge Criticizes Local Casino’s Role in Crime Trends
Industry
October 21, 2025
Embark on a Thrilling Ride in NetGaming’s Fly High
Sports
October 21, 2025
NJ Councilman Faces 18 Charges in Illegal Gambling Case
Industry
October 20, 2025
Whale.io Debuts Crock Dentist Along With Special NFT Collection
Casino
October 20, 2025
Hostage Standoff Unfolds at Foxwoods Resort Casino
Legal
October 20, 2025
Ex-Raketech Employee Lands 4-Year Jail Sentence for Embezzlement
Industry
October 17, 2025
iGaming Discussions in Virginia Continue as Bill Is Put on Hold
Legal
October 17, 2025
Crésus Casino CEO Faces Illegal Gambling Charges
Casino
October 17, 2025
Kickapoo Lucky Eagle Casino Acts in Wake of Mass Shooting