Cyber Hacking News

15,000 sites hacked in massive Google SEO poisoning campaign

0

Around 15,000 websites were compromised in a massive black hat search engine optimization (SEO) campaign where the visitors were redirected to a fake Q&A discussion forum.

Sucuri, which first spotted the attacks, said that each compromised site contains approximately 20,000 files used as part of the search engine spam campaign, with most of the sites being WordPress.

According to the researchers, the threat actors’ goal is to generate enough indexed pages to increase the fake Q&A sites’ authority and thus rank better in search engines.

The campaign likely primes these sites for future use as malware droppers or phishing sites, as even a short-term operation on the first page of Google Search, would result in many infections.

Another scenario, based on the existence of an ‘ads.txt’ file on the landing sites, is that their owners want to drive more traffic to conduct ad fraud.

Sucuri reports that the hackers are modifying WordPress PHP files to inject the redirects to the fakes Q&A discussion forums.

In certain cases, the attackers drop their own PHP files on the targeted site, using random or pseudo-legitimate file names.

The infected or injected files contain malicious code that checks if the website visitors are logged in to WordPress, and if they’re not, redirects them.

The browsers will have JavaScript loaded that redirects users to a Google search click URL that redirects users to the promoted Q&A site.

Using a Google search click URL increases performance metrics on the URLs in the Google Index to make it appear as if the sites are popular, hoping to increase their ranking in the search results.

Also, redirecting through Google search click URLs makes the traffic look more legitimate, possibly bypassing some security software.

However, Sucuri couldn’t identify how the threat actors breached the websites used for redirections. It likely happens by exploiting a vulnerable plugin or brute-forcing the WordPress admin password.

The users are recommended to update all WordPress plugins and website CMS to the latest version and enable two-factor authentication (2FA) on admin accounts.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

US DoJ seizes $3.36B worth Bitcoin from Silk Road hacker

Previous article

Canadian food retail giant Sobeys hit by ransomware

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *