HomeSecurity15,000 websites compromised in massive Google SEO poisoning campaign

15,000 websites compromised in massive Google SEO poisoning campaign

Hackers are compromising thousands of websites to redirect visitors to fake Q&A discussion forums in a massive black hat Google SEO campaign.

See also: Google partners with Renault to develop a Software Defined Vehicle

Google SEO

Sucuri was the first to spot the attacks and reports that each compromised site it found contained around 20,000 files. The campaign mostly targets WordPress.

The researchers believe that the hackers' ultimate goal is to create more websites in order to make the fake question and answer websites appear legitimate and, as a result, rank higher in search engines.

By placing these websites at the top of Google Search, the campaign is more likely to succeed in future efforts, such as infecting computers with malware or attempting to obtain personal information through phishing.

If there is an “ads.txt” file on the destination website, it is possible that the owner wants to commit ad fraud, driving more traffic there.

Sucuri reports that hackers are modifying WordPress PHP files, such as 'wp-singup.php', 'wp-cron.php', 'wp-settings.php', and others, to redirect users to fake discussion forums without their knowledge.

Sometimes, attackers leave behind their own PHP files on the website they just attacked, using names that could easily be mistaken for legitimate files (“wp-logln.php” is an example).

The infected or injected files contain malicious code that checks if site visitors are logged into WordPress and if they are not, redirects them to a URL containing a malicious image.

See also: Google Lens: The company integrates it into the search bar

However, instead of an image, browsers will receive a JavaScript that redirects users to the promoted question and answer site via a URL that clicks into Google search.

15,000 websites compromised in massive Google SEO poisoning campaign

By including a clickable URL in Google search, website owners increase their chances of ranking higher in search results because this tricks Google into thinking the site is popular.

The PNG image file uses the 'window.location.href' function to create a Google search redirect result to one of several targeted domains, including:

  • en.w4ksa[.]com
  • peace.yomeat[.]com
  • qa.bb7r[.]com
  • en.ajeel[.]store
  • qa.istisharaat[.]com
  • en.photolovegirl[.]com
  • en.poxnel[.]com
  • qa.tadalafilhot[.]com
  • questions.rawafedpor[.]com
  • qa.elbwaba[.]com
  • questions.firstgooal[.]com
  • qa.cr-halal[.]com
  • qa.aly2um[.]com

See also: Google Assistant: Gets new kid-friendly voices and parental controls

For optimal security, it is recommended that you upgrade all of your WordPress plugins and your website's CMS to the latest version. Additionally, we recommend enabling two-factor authentication (2FA) on all administrator accounts.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS