Key takeaways

  • SEO spam hacks create or inject spam content that search engines see but site owners often do not.
  • The Japanese keyword hack generates thousands of auto-created pages; the pharma hack injects drug and casino links.
  • Cloaking by user agent is the reason your site looks clean in your browser but spammy in Google.
  • Clean files, database and .htaccess together, and check Search Console for owners the attacker added.
  • Recovery in search takes time: remove the spam, return 404 or 410 for spam URLs and resubmit your sitemap.

What is an SEO spam hack?

An SEO spam hack is a compromise where attackers use your website's reputation to rank their own content. They create spam pages under your domain or inject hidden links into existing pages, promoting counterfeit goods, pharmacies, gambling or scams. Your site becomes free search engine real estate for someone else, and your own rankings suffer.

Two variants account for most of the SEO spam clean-ups we see:

Japanese keyword hackPharma hack
What appears in GoogleThousands of new URLs with Japanese titles, often selling branded goodsYour real pages with drug, casino or loan keywords in the titles or snippets
How it worksAuto-generated pages served by a PHP script or rewrite rulesHidden links and text injected into existing pages or the database
Typical locationNew PHP files, .htaccess rewrites, fake sitemapsTheme files, wp_options, wp_posts, plugin files
Visible to you?Usually not, unless you visit a spam URL directlyUsually not; shown only to search engine crawlers

Both are covered by Google's spam policies, and a site that hosts them can be flagged in Search Console under Security issues or lose visibility altogether. If Google is already warning visitors, see our guide to removing a Google blacklist warning.

How do you know if your site has an SEO spam hack?

The quickest test is a site: search in Google for your domain. If results show Japanese characters, pharmacy terms or pages you never created, you almost certainly have an SEO spam hack. Confirm it by fetching your site as a search engine crawler, because the spam is usually hidden from normal visitors.

  • A site:example.co.uk search shows pages or titles you do not recognise.
  • Search Console shows a sudden jump in indexed pages, or new sitemaps you did not submit.
  • Search Console lists an owner or user under Settings > Users and permissions that you did not add.
  • Your real pages show odd snippets in search results but look normal in your browser.
  • Visitors arriving from Google are redirected, while direct visits are not.
# Compare what a normal browser and a crawler receive
curl -s -A "Mozilla/5.0" https://example.co.uk/ | grep -i "<title>"
curl -s -A "Googlebot/2.1 (+http://www.google.com/bot.html)" https://example.co.uk/ | grep -i "<title>"

# Infected result: crawler sees a different page
<title>Acme Shop | Handmade Garden Furniture</title>
<title>ブランド 財布 激安 通販 | Acme Shop</title>

Tip: some infections also check the visitor's IP address against known crawler ranges, so a changed user agent will not always reveal them. Search Console's URL Inspection tool shows exactly what Googlebot received.

How does SEO spam hide from site owners?

SEO spam hides using cloaking: code that checks who is asking for the page and serves spam only to search engine crawlers, or only to visitors arriving from a search engine. Logged-in administrators and direct visitors see the normal site, which is why these infections can run for months before anyone notices.

The snippets below are illustrative, defanged and truncated. They show the patterns to look for.

<?php $ua = strtolower($_SERVER['HTTP_USER_AGENT'] ?? '');
if (preg_match('/googlebot|bingbot|yahoo/', $ua)) {
    echo @file_get_contents('hxxp://spam-feed[.]example/p.php?h=' . ... ); exit;  [truncated]
}
/** Front to the WordPress application. ... */
# Rewrite rules sending made-up URLs to a spam generator
RewriteRule ^([a-z0-9]{6,})/?$ wp-includes/css/wp-mod.php?k=$1 [L]
RewriteRule ^sitemap-([0-9]+)\.xml$ wp-includes/css/wp-mod.php?sm=$1 [L]

# Standard WordPress block (keep)
# BEGIN WordPress
RewriteRule ^index\.php$ - [L]

The pharma hack more often lives in the database. Spam links are stored inside posts, widgets or serialised options and printed with CSS that hides them from human visitors.

<div style="position:absolute;left:-9999px"><a href="hxxps://cheap-pills[.]example/...">buy ...</a> [truncated]

Security triage

Is your site showing any of this?

Tell us what you’re seeing in two minutes and we’ll tell you what it means and what to do next. Hacked right now? Get emergency help.

Start the triage

How do you remove the Japanese keyword hack or pharma hack?

Remove SEO spam by cleaning three places together: the files that generate or inject the spam, the database where content and options are stored, and the server configuration such as .htaccess. Then remove any attacker access to Search Console. Missing any one of these usually means the spam regenerates within days.

  1. Back up first. Take a full copy of files and database for evidence and rollback.
  2. Find the generator. Search for recently modified PHP files, unfamiliar files in wp-includes and wp-content, and code that checks user agents or referrers.
  3. Reinstall core, plugins and themes. Replace them with clean copies from official sources rather than editing infected files.
  4. Clean .htaccess. Restore the standard WordPress rules and remove any rewrites to unfamiliar scripts, in every directory.
  5. Clean the database. Search posts, options and widgets for spam terms, hidden links and scripts.
  6. Secure Search Console. Remove unknown owners and their verification files or DNS records, and delete sitemaps you did not submit.
  7. Close the entry point. Update or remove the vulnerable component, remove rogue admin users and rotate credentials.
# Recently changed PHP files, and user-agent checks in code
find /var/www/example.co.uk -name "*.php" -mtime -60 -type f
grep -rlE "HTTP_USER_AGENT.*(googlebot|bingbot)" /var/www/example.co.uk --include="*.php"

# Search the database for common spam terms and hidden links
wp db search "viagra|cialis|casino|left:-9999px" --regex --all-tables
wp db query "SELECT option_name FROM wp_options WHERE option_value LIKE '%display:none%<a %'"

# Verification files from unknown Search Console owners
ls /var/www/example.co.uk/google*.html

Warning: do not run blanket search-and-replace on serialised WordPress data with raw SQL. Changing string lengths corrupts serialised options. Use WP-CLI or clean the entries by hand.

How do you recover search rankings after an SEO spam hack?

Once the site is clean, make sure every spam URL returns a 404 or 410 status, resubmit your real sitemap and, if Google flagged the site, request a review in Search Console. Rankings usually recover gradually as Google recrawls, and there is no switch that clears thousands of spam URLs overnight.

  • Spam URLs must not return 200. A clean site will naturally return 404 for pages that never existed. A 410 can signal permanent removal more clearly.
  • Do not redirect spam URLs to your homepage. Mass redirects can look like soft 404s and slow the clean-up.
  • Use the Removals tool sparingly. It temporarily hides URLs from results; it does not deindex them permanently. It is useful for the most visible or embarrassing spam.
  • Resubmit your real sitemap and delete any sitemaps the attacker added.
  • Request a review under Security issues only after the clean-up is complete. A failed review delays recovery.
# Spot-check spam URLs from your site: search
curl -s -o /dev/null -w "%{http_code}\n" https://example.co.uk/a8f3kd2/
200   # still infected
404   # clean

Our Google blacklist removal service handles the clean-up and review request for you.

How do you stop SEO spam coming back?

SEO spam returns when the generator script, a backdoor or the original vulnerability is left behind. Prevent it by keeping plugins and themes updated, removing anything unused, blocking PHP in uploads, auditing admin users and Search Console owners, and monitoring for new files and sudden changes in indexed pages.

Attackers who run SEO spam campaigns often leave webshells so they can refresh their content, so treat any spam hack as a full compromise. Our guides on webshells and why malware keeps coming back explain what else to look for, and the WordPress hardening checklist covers prevention.

PatientZero finds the generator, cleans files, database and configuration in one pass, closes the entry point and monitors for anything returning, with unlimited malware removal on every plan. Start with our security triage or see our hacked website repair service.

Frequently asked questions

Why can't I see the Japanese spam pages on my site?

The infection uses cloaking. It shows spam only to search engine crawlers or to visitors arriving from a search engine, while you see your normal site. Use Search Console's URL Inspection tool, or fetch the page with a crawler user agent, to see what Google sees.

How long does it take for spam pages to disappear from Google?

It depends on how often Google recrawls your site and how many spam URLs were created. Some disappear within days of returning 404, others take weeks. The Removals tool can temporarily hide the most visible ones while recrawling happens.

Is the pharma hack dangerous for my visitors?

Often it is aimed at search engines rather than visitors, but it means an attacker can change your site's content, and many variants also redirect visitors to scam pharmacies. Treat it as a full compromise: the same access could be used for more harmful malware.

Why is there an extra owner in my Google Search Console?

Attackers often verify themselves as owners so they can submit their own sitemaps and speed up indexing of spam pages. Remove the unknown owner, delete the verification file or DNS record they used, and review any sitemaps they submitted.

Can I just delete the spam pages in WordPress?

Usually the spam pages are not WordPress posts at all. They are generated on the fly by a hidden script or rewrite rules, so there is nothing to delete in the dashboard. You need to remove the generator from the files and configuration.

PatientZero Incident Response Team · Digital forensics and incident response

Written by the PatientZero incident response team: the engineers who investigate and clean compromised WordPress sites and Linux servers every week.