Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×
Security

Hackers Exploit Websites To Give Them Excellent SEO Before Deploying Malware (zdnet.com) 11

schwit1 shares a report from ZDNet: Cyberattackers have turned to search engine optimization (SEO) techniques to deploy malware payloads to as many victims as possible. According to Sophos, the so-called search engine "deoptimization" method includes both SEO tricks and the abuse of human psychology to push websites that have been compromised up Google's rankings. SEO optimization is used by webmasters to legitimately increase their website's exposure on search engines such as Google or Bing. However, Sophos says that threat actors are now tampering with the content management systems (CMS) of websites to serve financial malware, exploit tools, and ransomware.

In a blog post on Monday, the cybersecurity team said the technique, dubbed "Gootloader," involves deployment of the infection framework for the Gootkit Remote Access Trojan (RAT) which also delivers a variety of other malware payloads. The use of SEO as a technique to deploy Gootkit RAT is not a small operation. The researchers estimate that a network of servers -- 400, if not more -- must be maintained at any given time for success. While it isn't known if a particular exploit is used to compromise these domains in the first place, the researchers say that CMSs running the backend of websites could have been hijacked via malware, stolen credentials, or brute-force attacks.

This discussion has been archived. No new comments can be posted.

Hackers Exploit Websites To Give Them Excellent SEO Before Deploying Malware

Comments Filter:
  • by Rosco P. Coltrane ( 209368 ) on Wednesday March 03, 2021 @09:05AM (#61119180)

    SEO optimization is used by webmasters to legitimately increase their website's exposure

    SEO is used to artificially boost a website's exposure. Legitimate exposure would be the site ranking up by virtue of its content, quality or attractiveness alone.

    • Yeah, that doesn't happen. Even if you've got a great site, Google doesn't look at it that way. It looks at sites at a very particular way, and if your site doesn't conform to what they think it should be, you'll never get on page 1 of the rankings. And if you're not on page 1, hardly anybody clicks through to page 2. And God forbid if your site is political because Google can and will demote you to page 134 of the search listings if they detect crimethink on your site.
  • "... SEO optimization is used by webmasters to legitimately increase their website's exposure on search engines such as Google or Bing. "

    I'd say rather, it's used by legitimate webmasters to raise their site rankings, because it's still "gaming" the algorithms.

    Hint: if search engine authors are constantly trying to block what you're doing, you can't really call the technique legitimate.

  • by sabbede ( 2678435 ) on Wednesday March 03, 2021 @09:29AM (#61119230)
    SEO optimization is a legitimate business they could do quite well with. Why not just charge for what they're doing as the first step of the attack and avoid the hassle of being a criminal a-hole?
    • Same reason they don't squeegee windshields for spare change. Too much competition.
    • Very few people who don't "have SEO" want to pay for it. Surely you must have received emails saying "Hey - I just visited your great website, but I noticed it wasn't in the first page of Google for common searches"? I get them all the bloody time, and no, I haven't ever taken them up on the offer for an 'assessment'.

      The people sending me spam emails, and these malware people don't make your site better - they add content to pages that make it turn up in more common search queries. Let's say your site is al

  • To aggressively remove spam and spammers from forums and comments.

    Hey, wait! I didn't mean ME!

  • According to Sophos, the so-called search engine "deoptimization" method

    If the stuff that non-malware-distributors do is SEO, so is the stuff that malware distributors do. In both cases it's optimising their (or their client's) site for search engines and deoptimising the search engines for people who want to find useful content.

  • Some real (biological) viruses fix faulty DNA to make infected cells healthier and more able to produce the offspring of the virus.

"More software projects have gone awry for lack of calendar time than for all other causes combined." -- Fred Brooks, Jr., _The Mythical Man Month_

Working...