ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

15,000 websites hijacked for massive Google SEO poisoning campaign

Cybersecurity researchers at Sucuri have discovered a massive black hat search engine optimization (SEO) campaign run by hackers by hijacking almost 15,000 websites to redirect visitors to fraud Q&A discussion forums.

 

A report from Sucuri stated that the campaign was first identified in September 2022, when the team noticed an increase in WordPress malware that was using ois[.]is to direct website visitors to fake Q&A sites.

 

The PHP files ’wp-singup.php,’ ’wp-cron.php,’ ’wp-mail.php,’ ’wp-settings.php,’ and ’wp-blog-header.php’ are among those modified by the hackers to inject the redirects, according to Sucuri. Sometimes, the attackers upload their PHP files to the targeted website under fictitious or random file names, such as "wp-logln.php."

 

Most compromised websites are WordPress-based, and each contains about 20,000 files used in the campaign to spam search engines. According to the researchers, the threat actors aim to produce enough indexed pages to boost the authority of the fictitious Q&A sites and help them rank higher in search results.

 

The malicious code in the injected or infected files checks to see if website visitors are logged into WordPress. If not, it sends them to ois.is/images/logo-6.png. Browsers won’t receive an image from this URL; instead, JavaScript will be loaded, rerouting users to a Google search URL that will take them to the promoted Q&A site. Additionally, using Google search click URLs to redirect makes the traffic appear more legitimate and may allow some security software to be bypassed.

 

Increasing performance metrics on URLs in the Google Index using a Google search click URL makes it appear that the websites are popular to raise their position in the search results. Additionally, using Google search click URLs to redirect makes the traffic appear more legitimate and may allow some security software to be skipped. It is advised for users to enable two-factor authentication (2FA) on admin accounts and update all WordPress plugins and website CMS to the most recent version.

 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543