• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

Malware Redirects 15,000 Sites in Malicious SEO Campaign

You are here: Home / General Cyber Security News / Malware Redirects 15,000 Sites in Malicious SEO Campaign
November 10, 2022

Security researchers have spotted an intriguing malware campaign designed to increase the search motor rankings of spam web-sites below the management of threat actors.

Over 15,000 WordPress and other web sites have been redirected to the spam Q&A web sites, according to Sucuri. The hackers are employing modified WordPress PHP data files and, in some situations, their own PHP information to reach the redirects, with focused internet sites on ordinary that contains 100 contaminated data files every.

The location spam web sites, of which Sucuri has so considerably located 14, have their servers hidden guiding a CloudFlare proxy.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


“The websites appear to be to be using the identical Q&A pattern and are crafted using the Issue2Solution (Q2A) open source Q&A platform. According to their website, this platform is currently powering over 24,500 internet sites in 40 languages,” the seller described.

“The attackers’ spam web pages are populated with a variety of random issues and responses identified to be scraped from other Q&A internet sites. Numerous of them have cryptocurrency and economic themes.”

Despite the fact that no destructive exercise has been detected on these spam sites as but, the actors at the rear of this campaign could “arbitrarily include malware” to them or redirect website visitors yet again to malicious 3rd-party sites, Sucuri warned.

“It’s attainable that these poor actors are simply attempting to persuade Google that actual men and women from distinctive IPs applying distinctive browsers are clicking on their search outcomes. This technique artificially sends Google signals that all those pages are carrying out perfectly in research,” the seller extra.

“If this is the case, it’s a fairly clever black hat Web optimization trick that we have almost never seen made use of in enormous hack strategies. However, its impact is questionable presented that Google will be getting heaps of ‘clicks’ on look for outcomes without any actual searches currently being carried out.”

This idea is backed by the actuality that the second degree domains of the Q&A web sites “seem to belong” to the same folks, it additional.

The marketing campaign is relatively strange in that only 13% of all Web optimization spam infections are categorized as a destructive redirect, in accordance to Sucuri.


Some pieces of this short article are sourced from:
www.infosecurity-journal.com

Previous Post: «citrix issues patches for critical flaw affecting adc and gateway Citrix Issues Patches for Critical Flaw Affecting ADC and Gateway Products
Next Post: Some 98% of Global Firms Suffer Supply Chain Breach in 2021 Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.