Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Researchers Uncover “Haxor” SEO Poisoning Marketplace
News

Researchers Uncover “Haxor” SEO Poisoning Marketplace

Team-CWDBy Team-CWDJanuary 26, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Security researchers have discovered an expansive backlink marketplace designed to help threat actors get malicious web pages ranked higher in search listings.

Fortra’s Intelligence and Research Experts (FIRE) found the “HaxorSEO” or “HxSEO” operation on Telegram and WhatsApp. It offers a Google Sheet of over 1000 backlinks to pre-compromised but legitimate domains.

“These domains are typically 15-20 years old and are marketed alongside a selection of ‘trust’ scores to advertise how effective the purchased backlink would be for increasing search engine rankings,” explained Fortra.

“Once payment is made, the group will add the backlink along with the malicious address to the legitimate domain, increasing the buyer’s likelihood of successfully achieving their goals.”

Read more on SEO poisoning: SEO Poisoning Targets Chinese Users with Fake Software Sites

Each legitimate website is compromised with a webshell that enables Haxor to upload a malicious backlink to the site. By buying and then inserting these links into their sites, threat actors can boost search rankings, drawing unsuspecting visitors to phishing pages designed to harvest their credentials or install malware.

In some cases, HxSEO’s successful optimization of fraudulent banking login pages meant that they ranked higher than the legitimate equivalents they were ripping off, said Fortra.

The vendor claimed that Haxor can also negatively impact the SEO score of legitimate pages that are being imitated, by using bad backlinks hosted on spammy, low-authority sights.

Low Cost, Big Impact

The operation offers backlinks for just $6 per listing, and automatically injects the necessary code into the compromised site, making this a highly attractive service for threat actors.

“This combined with the difficulty of spotting the backlinks in a search result inevitably leads to attacks at scale,” it warned.

The HxSEO market itself lists the malicious backlinks alongside common SEO metrics that indicate the authority and strength of a domain/webpage.

“Page authority (PA), domain authority (DA), and domain rating (DR) predict how effective the site is for SEO poisoning, with the domain rating giving the strongest indicator at how effective the domain’s backlink profile is,” Fortra explained.

“SS or spam score estimates the likelihood of a domain being penalized or considered spam. The list typically advertises 100-150 compromised websites at a given time, with forgotten academic journal webpages a clear preference.”

The Hexor team targets vulnerable php components and WordPress plugins most often, using a variety of file upload and remote code execution exploits, the report noted.

Users Urged to Be Cautious

Although search engines are continuously hunting for malicious activity like this, a steady supply of new domains, fresh backlinks and content updates can keep operations like Hexor ticking over. Further, customers using these services likely only require a malicious phishing site to be up and running for a few days or weeks, said Fortra.

The threat intelligence firm has been working with relevant domain service providers, web owners and search engines to take down the malicious pages. However, it also encouraged users to improve their awareness of such schemes.

“Users are advised to be wary of URLs that they access via search engines, especially banking login pages. A best practice is to bookmark sensitive login pages, like your bank login, rather than locating it via a search engine,” it concluded.

“Make sure to verify that the domain in the URL is legitimate and keep an eye out for lookalike domains that may have minor spelling differences you wouldn’t notice immediately. If you are unsure, contact your bank and ask them to identify the correct login page.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCERT/CC Warns binary-parser Bug Allows Node.js Privilege-Level Code Execution
Next Article LastPass Warns of Fake Maintenance Messages Targeting Users’ Master Passwords
Team-CWD
  • Website

Related Posts

News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
News

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Can password managers get hacked? Here’s what to know

November 14, 2025

Is it OK to let your children post selfies online?

February 17, 2026

Fixing trivial passwords is as easy as 123456

May 7, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.