Ghost Folders: “Directory Shadowing” Hack Hijacks WordPress SEO
ID: 6d94f83c-adba-52a3-a2a2-6061fef745f5
STIX ID: report--6d94f83c-adba-52a3-a2a2-6061fef745f5
Feed Name: securityonline.info
A Sucuri analysis details a stealthy WordPress malware campaign called "directory shadowing" in which attackers create physical directories matching site permalinks (e.g., /about-us/) so the webserver serves attacker-controlled content instead of the legitimate WordPress page; the attack uses files named index.php, indexx.php (clean copy), and readme.txt (spam), performs User-Agent checks to cloak content to search engine crawlers, and requires removing the malicious directories and requesting re-indexing to remediate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
