logo

Ghost Folders: “Directory Shadowing” Hack Hijacks WordPress SEO

ID: 6d94f83c-adba-52a3-a2a2-6061fef745f5

STIX ID: report--6d94f83c-adba-52a3-a2a2-6061fef745f5

Feed Name: securityonline.info

Threat Score
55/100

Date Published: 2026-02-05

Date Updated: 2026-04-23

Author: Ddos

...
...

A Sucuri analysis details a stealthy WordPress malware campaign called "directory shadowing" in which attackers create physical directories matching site permalinks (e.g., /about-us/) so the webserver serves attacker-controlled content instead of the legitimate WordPress page; the attack uses files named index.php, indexx.php (clean copy), and readme.txt (spam), performs User-Agent checks to cloak content to search engine crawlers, and requires removing the malicious directories and requesting re-indexing to remediate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.