Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Hackers Exploit Thousands of Websites to Promote Online Pharmacies and Adult Sites

by The Gurus
June 9, 2016
in Editor's News
Share on FacebookShare on Twitter

Imperva, Inc. (NYSE: IMPV), committed to protecting business-critical data and applications in the cloud and on-premises, today released its new Hacker Intelligence Initiative (HII) Report entitled: “Black Hat SEO: A Detailed Analysis of Illegal SEO Tactics.” The report details how researchers at the Imperva Defense Center (IDC) discovered a long-running and still active illegal attack that has been exploiting vulnerabilities in thousands of legitimate websites to increase the SEO results for illicit websites.
One of the largest influencers of SEO page rank is how many other sites contain links back to the page, and how highly the referring sites themselves are ranked. There is significant monetary and brand value in having as many respectable and popular sites link to the promoted page as possible. In the campaign studied in the HII Report, the attackers compromise websites or take over computers in order to create unauthorized links that point back to their clients’ websites. IDC researchers found the attackers compromise the content management systems of vulnerable websites to create fake blogs with links pointing back to online pharmacies in order to increase the SEO rankings of the online pharmacies. The illegal SEO attack campaign identified by Imperva is persistent, lasts over many months and promotes dozens of websites – presumably those of the paying customers of the attacker – most of which are online pharmaceutical retailers or adult websites.
The attackers use botnets to amplify the number of websites they compromise. Botnets are networks of remote-controlled computers and devices, or “bots,” that are infected with malware. Attackers can create their own botnets or even hire or rent botnets as a service. Cybercriminals remotely control the botnets for their own purposes, unbeknownst to the devices’ owners. The botnets launch SQL injection (SQLi), HTML link injection and comment spam attacks that exploit vulnerabilities in reputable websites and content management systems. The attackers use these vulnerabilities to create links from the compromised sites back to the promoted, illicit pages. This boosts the search engine rankings of the illicit pages. Over 700 hosts (IP addresses) were used by the botnet during the period studied in the HII Report to launch these SQLi and HTML link injection attacks.
“Automatic attack tools, known as malicious bots, are deployed every second to achieve widespread attacks on websites, and more sophisticated attackers use a distributed network of bots to launch attacks,” said Amichai Shulman, Co-founder and CTO of Imperva. “While it is common to see many variations on the same attack vector comprise these campaigns – such as comment spam used to improve rankings of promoted sites – it is unusual to identify a multi-faceted, long-term campaign run with coordination from the same botnet in the wild.”
“This kind of attack has the potential to impact a legitimate website’s customer experience and brand value, and it could even break the functionality on some website applications,” Shulman explained. “These SQLi attacks are typically referred to as “gateway” attacks and can test the water for more serious attacks to come. Websites can be thought of as the highway to business-critical data, so owners of those that have been targeted should be particularly worried as often SQLi attacks are used to steal data. This definitely serves as a reminder of how relentless cybercriminals are, and the need to bolster website security.“
The full report can be downloaded here and the infographic here.

ShareTweet
Previous Post

Microsoft's BITS file transfer tool fooled into malware distribution

Next Post

Stockpiling bitcoin to pay hacking ransoms is a highly dangerous game to play

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol