Thousands of websites hijacked for posioned Google SEO campaign

An image of security icons for a network encircling a digital blue earth.
(Image credit: Shutterstock)

Cybercriminals have launched a major malicious SEO campaign with the goal of promoting obscure, low-quality Q&A sites, new research has found. 

A report from cybersecurity researchers Sucuri states that a unique piece of WordPress malware sits at the center of this campaign.

According to the report, the campaign was first observed in September 2022, when the team spotted a surge in WordPress malware that was redirecting website visitors to fake Q&A sites via ois[.]is. The goal of the malicious redirects was to boost the authority of these Q&A sites in the eyes of search engines - and in total, almost 15,000 websites have been affected, so far.

Hundreds of infected files

What makes this campaign stand out from all the other malicious SEO campaigns is that the threat actors aren’t really trying hard to hide the malware on these sites. In fact, they’re doing the exact opposite. 

Usually, website malware infections limit themselves to a small number of files, to be able to fly under the radar. With this campaign, the average website has more than 100 infected files, making it somewhat unique in that respect. Most commonly, the malware would affect core WordPress files, such as ./wp-signup.php, ./wp-cron.php, ./wp-links-opml.php, ./wp-settings.php, and ./wp-comments-post.php. 

However, this malware was also observed infecting malicious .php files created by other unrelated malware campaigns, as well.

“Since the malware intertwines itself with the core operations of WordPress the redirect is able to execute itself in the browsers of whoever visits the site,” the researchers explained.

Redirects to spam websites are hardly a novel approach to cybercrime, Sucuri’s researchers added. In fact, more than half (50%) of the malware the company cleaned up last year was SEO spam. Also, spam takes up more than a third of all malware detections from its SiteCheck tool. 

“That said, spam redirects in particular are not as common with just over 13% of all SEO spam infections classified as a malicious redirect,” the company concluded.

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A close-up of an interent search bar with 'http://ww' visible
Major website hijacking scam sees over 35,000 sites attacked, redirected to gambling sites, so be on your guard
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Thousands of WordPress websites hit in new malware attack, here's what we know
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over 10,000 WordPress sites found showing fake Google browser update pages to spread malware
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
WordPress users targeted by devious new credit card skimmer malware
NordVPN
US hit with over 1.9 billion malware threats last year - here's how to stay safe
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over