Search engine listings littered with dangerous malware

Magnifying glass enlarging the word 'malware' in computer machine code
(Image credit: Shutterstock)

There are currently an estimated 4.1 million websites infected with malware worldwide.

This is the conclusion of a new report from certificate lifecycle management (CLM) provider Sectigo, based on an analysis of more than 14 million websites conducted by its website protection and monitoring arm, SiteLock.

What’s worse, almost all of these infected websites (93%) are not blacklisted and therefore appear in public search engine listings. The most prevalent malware variants are Filehacker, which is found in more than a third of infected websites, and Backdoor (31%).

TechRadar needs you!

We're looking at how our readers use VPNs with different devices so we can improve our content and offer better advice. This survey shouldn't take more than 60 seconds of your time. Thank you for taking part.

>> Click here to start the survey in a new window <<

Bot traffic

To infect many millions of websites is an impressive feat. So, how do threat actors do it?

Sectigo believes the majority automate their attacks; bots in 2021 accounted for 5.5 times more traffic than humans, amounting to more than 2,300 weekly average bot visits per site. At the same time, the volume of human traffic decreased. 

While not all bot traffic is malicious, the part that is causes plenty of headache all around. 

“Malicious bots can programmatically visit websites and identify vulnerabilities in code to execute their attacks, such as stealing data or inserting malware,” said Jason Soroko, CTO of PKI at Sectigo. 

“The public internet is a very dangerous place and is increasingly getting worse. Don’t commit the fallacy of the underdog, SMB websites have enormous value to bad actors because they have customer data and can be used for phishing attacks. It’s not just about fraud, either. If websites handle payments, they’re obvious targets, too. The content management system platforms SMBs rely on may not protect against these threats. In fact, they are inherently difficult to secure.”

In total, endpoints are attacked 172 times per day, meaning they receive eight attacks every minute. Nearly half (48%) of SMB website owners believe they are too small to target. At the same time, more than half of them have already been breached.

Given the broad range of threats, businesses require a comprehensive security solution, Sectigo concluded.

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Thousands of WordPress websites hit in new malware attack, here's what we know
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over 10,000 WordPress sites found showing fake Google browser update pages to spread malware
NordVPN
US hit with over 1.9 billion malware threats last year - here's how to stay safe
Android phone malware
Over 25 new malware variants created every single hour as smart device cyberattacks more than double in 2024
A close-up of an interent search bar with &#039;http://ww&#039; visible
Major website hijacking scam sees over 35,000 sites attacked, redirected to gambling sites, so be on your guard
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
Latest in Security
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Latest in News
Buzz Lightyear Space Ranger Spin Rennovations
Disney’s giving a classic Buzz Lightyear ride a tech overhaul – here's everything you need to know
Hisense U8 series TV on wall in living room
Hisense announces 2025 mini-LED TV lineup, with screen sizes up to 100 inches – and a surprising smart TV switch
Nintendo Music teaser art
Nintendo Music expands its library with songs from Kirby and the Forgotten Land and Tetris
Opera AI Tabs
Opera's new AI feature brings order to your browser tab chaos
An image of Pro-Ject&#039;s Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead