forumNew topic

Hit with an SEO poisoning attack — what's the usual goal, and how do you spot it?

JJülide A***Member
Job title
Marketing manager
Sector
Real estate
Organization type
sole proprietorship
Joined
May 2024
Message
134
#1

We're a mid-sized industrial machinery parts manufacturer in Bursa. Our WordPress site has been live for about 6 years, and we consistently ranked on page one for core industry keywords. We allocate a regular monthly budget of 12,000 TL for maintenance and technical upkeep. Last week, we were shocked by a screenshot sent by one of our dealers.

When you visit the site from a desktop browser, everything looks totally normal. But when users click through from search engine results on a phone, they get redirected to bizarre sites pushing fake betting platforms and illegal pharmaceuticals. Even worse, thousands of gibberish pages written in Asian scripts have started appearing under our site title in Google search results.

Why do attackers resort to such a sneaky method instead of just hacking the site and defacing the index page? What is the main goal behind these attacks, and how can we trace and wipe this garbage from our server for good?

VVolkan A***Veteran
Job title
Software Architect
Joined
Apr 2023
Message
312
Most Helpful#2

Short answer: The most common purpose of SEO poisoning is to exploit your domain age, search engine authority, and clean reputation to quietly funnel organic traffic to scam, gambling, or malware sites. Instead of taking down your site, attackers act as parasites, monetizing your traffic behind the scenes without getting noticed.

These attacks rely on "cloaking." Once the malicious code infects the server, it checks incoming visitor signals. If the visitor is the site owner or someone typing the URL directly, it serves the clean page. But if the request comes from a Googlebot or a mobile search referrer, it triggers the spam content or redirect scripts. That's why you can go months without noticing it on desktop.

To detect and mitigate this, take the following steps: 1) Open your Search Console, inspect the URL structures of the indexed spam pages, and submit removal requests; 2) Compare your core server config files (.htaccess or web server configs) and WordPress core files against pristine copies byte by byte; 3) Scan your database post tables for obfuscated PHP payloads hidden via base64 or eval.

Once cleanup is complete, rotate all database, FTP, and hosting panel passwords, lock down server file write permissions, and submit a sanitized sitemap to the search console to request a fresh crawl.

note: I wrote this based on my own experience, it might not apply to everyone.

BBurak Ö***Expert
Job title
Data entry clerk
Sector
Sports and fitness
Organization type
cooperative
Joined
Mar 2022
Message
104
#3

SSH into your server and run a curl test spoofing the Googlebot user-agent. When you send a request disguised as a crawler from the terminal, you'll see the redirects and injected spam links right in the raw HTML response. They usually drop an obfuscated one-line include at the very top of wp-blog-header or index.php.

edit: typed from phone, sorry for typos.

BBerkMember
Job title
Real Estate Agent
Joined
Apr 2024
Message
102

Doki · Incident response support · 2026

#4

First thing to do is hop into search console and use the URL removal tool. Identify those weird script URL patterns and get them purged from cache and index immediately, otherwise your domain getting blacklisted within weeks is practically guaranteed.

İİbrahim G***MemberCommunity member
Joined
Mar 2024
Message
3
#5

Don't assume you're clean just because you scanned the files. These actors almost always set up server cron jobs that re-download the payload. You delete the file, midnight hits, the cron runs, and it pulls the same PHP right back from a remote host. You won't get rid of it until you scrub those scheduled tasks.

FFiliz Ö***Member
Job title
Operations manager
Sector
Seafood
Organization type
8-person team
Joined
Sep 2024
Message
383
#6

happened to us last year, spent two weeks hunting it down and turned out they got in through an old form plugin exploit and injected rows straight into the db then btw only fixed it by purging the plugin completely and restoring a clean database backup.

BBarışExpert
Job title
Chain supermarket
Organization type
regional distributor
Joined
Aug 2023
Message
148
#7

On our wholesale food site, 24,000 spam URLs got indexed overnight. We did the cleanup, but it took a full 5 months for the search results to be completely purged on Google's end and for us to win back our old organic keywords.

RRıdvan A***Veteran
Job title
Software developer
Sector
Leather
Organization type
two-branch business
Joined
Jan 2024
Message
12
#8

Is the server you're using a shared hosting account or a cloud server dedicated to you? If you're on shared space, could they have jumped into your directories because of a security hole in some completely unrelated other customer on the same server?

NNazlı T***MemberCommunity member
Joined
Apr 2025
Message
217
#9

The way the attack works basically consists of three steps: First, they get in through a vulnerability in an outdated theme or plugin. In the second step, thousands of virtual pages generated with spam keywords are served up to the search engine. In the third step, real users coming from these keywords are redirected to the target fake sites.

NNeslihan T***MemberCommunity member
Joined
Nov 2022
Message
226
#10

There are four mandatory steps that must not be skipped during cleanup: 1) Renew all database user passwords, 2) Reset the security keys (salt keys), 3) Delete the executable PHP files in the file upload folder, 4) Examine the access logs on the server side and close off the source of the initial breach.

SSerkan Ş***Member
Job title
Data entry clerk
Sector
Healthcare services
Organization type
family business
Joined
Dec 2025
Message
3
#11

you're right. when we decide without measuring we always end up in the same place.

everyone rushing into seo poisoning gets stuck at the same point. tbh that's all, sorry if I went on too long.

HHakan G***Member
Job title
Purchasing manager
Sector
Seafood
Organization type
300-person organization
Joined
Oct 2024
Message
185
#12

don't miss this: Trying to do this alne is the most expensive way.

most incidents start with a leaked password, not a vulnerability and btw if you post the result here, it will help others too.

NNecati B***Member
Job title
Content Editor
Sector
Tourism
Organization type
a company within a holding
Joined
May 2023
Message
249

Doki · SEO consulting · 2026

#13

i didn't know that.

EElif B***MemberCommunity member
Joined
Aug 2025
Message
1
#14

just a heads-up. the bigggest time-waster for us was not knowing who had the final say.

of course, it variies if your situation is different.

HHilal Y***Expert
Job title
Accounting Manager
Sector
Catering
Organization type
chain store
Joined
Aug 2025
Message
66
#15

Quick summary for newcomers: Taking measures without an inventory leaves doors you haven't seen open.

If I were you, I'd go this route.

KKayahanMember
Job title
Full-stack
Joined
Jun 2024
Message
118
#16

Here's how it went for us. If it's your first time, start small; scaling comes later.

The biggest time-waster for us was not knowing who had the final say. If I were you, Id go this route.

NNeslihan S***Member
Job title
Production planning
Sector
Retail
Organization type
two-branch business
Joined
Mar 2022
Message
95
#17

i agree and I'd like to emphasize that. don't hesitate to ask; those who don't ask always pay more.

hasty decisions become decisions you have to fix six months later. proven by experience.

MMusaNew member
Job title
Intercity freight
Joined
Oct 2024
Message
34
#18

There's one point I'm curious about. Don't hesitate to ask; those who don't ask always pay more.

Mistakes made on the seo poisoning side are usually reversible but expensive. Hope this helps.

EEmre A***MemberCommunity member
Joined
Nov 2024
Message
1
#19

My questions are cleared up, thanks. The biggest time-waster for us was not knowing who had the final say.

If 2FA is on, a stolen password alone is useless.

DDeniz K***ExpertCommunity member
Joined
Nov 2024
Message
154
#20

I'll try it.

Reply