Attackers are increasingly targeting legitimate business websites by injecting hidden HTML blocks containing links to third-party sites, often related to pornography or gambling. These hidden links are not visible to regular users but are detected by search engines and security solutions, which can result in the affected websites being miscategorized or flagged as unsafe. The presence of such links is a form of black hat SEO, where attackers manipulate search engine rankings by artificially inflating the link profile of their own or affiliated sites. Website owners are often unaware of the compromise until they notice a sudden drop in web traffic, receive complaints from users, or are alerted by security software that their site is being blocked or categorized as prohibited. The injected links typically contain relevant keywords and point to low-authority, unrelated domains, which further damages the reputation and search ranking of the victim site. Search engines penalize sites hosting these hidden links, causing them to lose visibility in search results and potentially harming their business prospects. The attack is not limited to any particular industry, with cases observed on sites ranging from manufacturers to law firms and online retailers. The technical method involves inserting invisible HTML elements that are ignored by users but parsed by automated systems. Detection can be challenging without specialized tools, but security solutions like those from Kaspersky can identify and block such compromised sites. The impact extends beyond search rankings, as clients may lose trust in the affected business if their security software flags the site or if they are inadvertently exposed to inappropriate content. Remediation involves thoroughly scanning the website’s codebase, removing unauthorized HTML blocks, and strengthening security to prevent future injections. Website administrators are advised to monitor their sites for unusual changes in traffic or categorization and to use reputable security tools for ongoing protection. The incident highlights the importance of regular website audits and prompt response to security alerts. Attackers exploit vulnerabilities in website management or outdated plugins to gain access and insert malicious content. Proactive measures, such as keeping software up to date and restricting administrative access, can reduce the risk of such SEO spam attacks. Ultimately, maintaining a clean and reputable web presence requires vigilance against these evolving black hat SEO tactics.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Kaspersky published an analysis describing a web-compromise pattern in which attackers inject hidden SEO link blocks into legitimate corporate websites, often linking to pornography, casino, and other low-reputation domains. The report outlined likely intrusion paths, common CSS hiding techniques, the reputational and search-ranking impact on victims, and recommended defensive measures.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 159 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.