TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Sucuri Blog

Joomla SEO Spam Injector: Obfuscated PHP Backdoor Hijacking Site Visitors

Puja Srivastava · 2026-04-16 · Read original ↗

ATT&CK techniques detected

1 predictions
T1071.001Web Protocols
32%
“in the infection three domains appear in this malware. two are active c2s. one is a dead decoy. - primary : cdn [. ] erpsaz [. ] com – primary c2 - fallback : cdn [. ] saholerp [. ] com – fallback c2, used automatically if the primary returns an empty response - doesn ’ t return …”

Summary

Joomla SEO Spam Injector: Obfuscated PHP Backdoor Hijacking Site Visitors

Overview

During a recent malware cleanup investigation, we encountered a compromised Joomla website where the site owner reported a strange issue. Their website displayed a large number of suspicious product links that had nothing to do with their business. These products were not added by the website owner and did not exist in their catalog.

Visitors and search engines were seeing pages that promoted unrelated products, raising immediate concerns about spam injection or remote content manipulation.

Continue reading Joomla SEO Spam Injector: Obfuscated PHP Backdoor Hijacking Site Visitors at Sucuri Blog.