Key takeaways

  • Redirect malware sends some or all visitors to scam pages, usually selectively so the owner does not notice.
  • Common triggers are mobile devices, first visits, and visitors arriving from search engines or social media.
  • The redirect can live in JavaScript, PHP, .htaccess, the database or the WordPress site URL settings.
  • Test as a first-time mobile visitor from Google, not as a logged-in administrator.
  • Remove every location at once and close the entry point, or the redirect returns.

What is a malicious redirect hack?

A malicious redirect hack is malware that sends visitors from your website to a page the attacker chooses: fake prize draws, tech-support scams, adult content, fake browser updates or crypto schemes. The attacker is paid for the traffic or profits from the scam, and your site's visitors and reputation carry the cost.

Redirect hacks are among the most visible website infections, and one of the most frustrating, because they are designed not to trigger for the site owner. Customers phone to say your site took them somewhere unpleasant, you check, and everything looks normal. That is not bad luck; it is the malware working as intended.

Left in place, a redirect hack can lead to browser warnings such as "Deceptive site ahead", removal from search results and advertising account suspensions. If you already see a warning, read our guide to removing Google blacklist warnings alongside this one.

Why does the redirect not happen when I visit my own site?

Redirect malware is conditional. It checks who is visiting before it acts, and typically skips logged-in administrators, repeat visitors, desktop browsers and people who typed the address directly. It targets first-time mobile visitors arriving from Google or social media, because they are least likely to report it and most likely to be fooled.

Common conditions we find in redirect code include:

  • Device. Only mobile user agents are redirected.
  • Referrer. Only visitors arriving from a search engine or social network.
  • Cookie. Only the first visit; a cookie is set so the same person is not redirected twice.
  • Login state. Anyone with a WordPress login cookie is excluded.
  • Time or frequency. Only at certain hours, or only a percentage of visits.

To reproduce it, test from outside your usual network, with no cookies, a mobile user agent and a search engine referrer:

# Simulate a first-time mobile visitor arriving from Google
curl -sIL -A "Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) Mobile/15E148" \
     -e "https://www.google.com/" https://example.co.uk/ | grep -iE "^(HTTP|location)"

HTTP/2 200
# Infected result
HTTP/2 302
location: hxxps://prize-claim[.]example/?s=acme-shop ...

Tip: JavaScript redirects will not show in curl. Use a private browser window on a phone, on mobile data, and follow a link from a Google search result to your site.

Where does redirect malware hide?

Redirect code hides in five main places: injected JavaScript in theme or plugin files, PHP code that runs before WordPress loads, .htaccess rewrite rules, scripts stored in the database, and altered WordPress site URL settings. Many infections use two or more at once, so finding one is not the end of the search.

LocationWhat to look forHow it behaves
JavaScript filesCode appended to theme or plugin .js files, often after thousands of spacesRedirect runs in the visitor's browser
PHP filesCode at the top of index.php, wp-config.php, functions.php or a must-use pluginServer sends a 302 before the page loads
.htaccessRewriteCond rules checking referrer or user agentWeb server redirects matching visitors
Database<script> tags in posts, widgets or optionsInjected into every page that shows that content
Site URL settingssiteurl or home changed in wp_optionsWhole site redirects, including the admin area

The snippets below are illustrative, defanged and truncated.

jQuery(function($){ $('.menu-toggle').on('click', ... ); });
;(function(){var r=document.referrer,u=navigator.userAgent;if(/google|facebook/i.test(r)&&/Mobi/i.test(u)&&
!document.cookie.match(/_vs=/)){document.cookie="_vs=1;max-age=86400;path=/";window.location=atob("aHh4cH...")}})(); [truncated]
RewriteCond %{HTTP_REFERER} (google|bing|facebook|instagram) [NC]
RewriteCond %{HTTP_USER_AGENT} (android|iphone|mobile) [NC]
RewriteRule ^(.*)$ hxxps://prize-claim[.]example/?r=... [R=302,L]
<p>Our handmade benches are built from FSC-certified oak...</p>
<script src="hxxps://cdn-stats[.]example/j/min.js?v=..."></script>

Security triage

Is your site showing any of this?

Tell us what you’re seeing in two minutes and we’ll tell you what it means and what to do next. Hacked right now? Get emergency help.

Start the triage

How do you find the redirect code?

Work from the outside in. First capture the redirect in action to see whether it is a server response or JavaScript, then search the matching location: files for PHP and JavaScript injections, .htaccess for rewrite rules, and the database for stored scripts. Checksums quickly show which core, plugin and theme files have been altered.

  1. Capture it. A 301 or 302 in the response headers means server-side code or .htaccess. A 200 followed by a change of page means JavaScript.
  2. Check the site URL settings. These are quick to rule in or out.
  3. Verify checksums. Any altered core or plugin file is a strong lead.
  4. Search files and database. Look for unfamiliar external script sources, atob, String.fromCharCode and referrer checks.
  5. Check every .htaccess. Not just the one in the web root.
# Site URL settings
wp option get siteurl
wp option get home

# Altered core and plugin files
wp core verify-checksums
wp plugin verify-checksums --all

# Referrer and user-agent checks in JavaScript and PHP
grep -rlE "document\.referrer|atob\(|fromCharCode|HTTP_REFERER" wp-content --include="*.js" --include="*.php"

# Scripts stored in the database
wp db search "<script" --all-tables --stats

# Every .htaccess file, with any redirect rules
find . -name ".htaccess" -exec grep -HnE "HTTP_REFERER|HTTP_USER_AGENT|R=30[12]" {} \;

Expect some legitimate matches: analytics, cookie banners and page builders use similar functions. Read each result rather than deleting everything that matches.

How do you remove redirect malware and stop it returning?

Remove redirect malware by cleaning every location together, replacing altered files with clean copies from official sources, then fixing the way the attacker got in. Redirect hacks are frequently re-installed by a webshell or cron job, so check for persistence before declaring the site clean.

  1. Back up for evidence, then put the site into maintenance mode if visitors are still being redirected.
  2. Reset site URL settings if they were changed, and remove any WP_HOME or WP_SITEURL values you did not set.
  3. Reinstall WordPress core, plugins and themes from official sources. For custom themes, compare against your version control or a known-clean copy.
  4. Clean the database, removing injected scripts from posts, widgets and options.
  5. Restore clean .htaccess files everywhere.
  6. Hunt for persistence: webshells, rogue admins, must-use plugins, cron jobs and modified wp-config.php.
  7. Close the entry point, rotate credentials and the WordPress salts, and clear every cache layer, including any CDN.
# Injected above the database settings (remove)
@include "\x2f\x76\x61\x72/tmp/.sess_8d1c..."; [truncated]

# Clean configuration
define( 'DB_NAME', 'acme_wp' );
define( 'DISALLOW_FILE_EDIT', true );

Do not forget the cache. Page caches and CDNs can keep serving the infected version after the files are clean. Purge them once the clean-up is complete, and test again as a first-time mobile visitor.

If the redirect keeps coming back, read why malware keeps coming back. If your shop's checkout was affected, also check for card skimmers, which often arrive through the same access.

When should you call in a specialist?

Call in help if the redirect returns after cleaning, if several sites on the same server are affected, if Google or a browser is already showing a warning, or if you run an online shop. Each of those suggests either deeper persistence or a real risk to customers that needs to be contained quickly.

PatientZero traces the redirect to every location it lives in, removes it along with any webshells, cron jobs and rogue users behind it, fixes the entry point and hardens the site. Our platform then monitors for new injected scripts and file changes, and unlimited malware removal is included on every plan.

Start with our security triage, see our hacked website repair service, or get emergency help if customers are being redirected right now.

Frequently asked questions

Why does my website redirect on mobile but not on desktop?

Redirect malware often targets mobile users only, because they are less likely to notice the address change and less likely to report it. The code checks the browser's user agent and redirects only phones and tablets. It is still the same infection and needs the same clean-up.

Can a plugin cause my site to redirect to spam?

Yes. A vulnerable plugin is a common way in, and attackers also inject redirect code into legitimate plugin files. Nulled or pirated plugins and themes frequently ship with redirect malware already included, so only install from official sources or the original developer.

Is my site redirecting because of my hosting?

Occasionally the problem is at DNS or hosting level, but most redirects come from code on your site. Check whether your DNS records point to your own server, then look for server responses and JavaScript on the site itself. A forensic scan quickly shows which it is.

Will clearing my cache fix the redirect?

No. Clearing the cache only removes stored copies of pages. If the malware is still in your files or database, the next visitor regenerates the infected page. Clean the site first, then purge every cache layer so visitors stop receiving the old infected copies.

Do I need to tell anyone my site was redirecting visitors?

If the attacker could have accessed personal data, you may have obligations under UK GDPR. A redirect on its own does not always involve personal data, but the access behind it might. Our guide to website hacks and GDPR breach reporting explains how to assess it.

PatientZero Incident Response Team · Digital forensics and incident response

Written by the PatientZero incident response team: the engineers who investigate and clean compromised WordPress sites and Linux servers every week.