WordPress

Common types of WordPress malware: backdoors, spam, redirects and cryptominers

Backdoors, spam injections, redirects and cryptominers behave completely differently. Understanding the type is the first step to getting rid of it.

”Hacked” is an umbrella term for very different things. A cryptominer steals your server power; a spam injection hijacks your SEO; a backdoor lets the attacker back in. Recognizing the type helps you understand the damage, how serious it is, and what the cleanup requires.

Backdoors

The most dangerous type, because it’s about access rather than a visible effect. A backdoor is hidden code — often obfuscated and tucked into an innocent-looking file — that lets the attacker back in anytime, even after you’ve ”cleaned up”. A single missed backdoor re-infects the whole site within days. That’s exactly why a real cleanup always starts by finding the entry point, not just the visible symptom.

Spam and SEO injections

This exploits your site’s credibility in Google’s eyes. The attacker injects hidden links, whole spam pages or keywords (often pills, casino, counterfeits) that rank on your domain’s authority. You rarely see anything yourself — but Google does, and when the flag comes your ranking collapses. This type is especially insidious because the damage is to your SEO, not the site’s function.

Malicious redirects

The code sends your visitors on to another site — often only on mobile, or only for visitors arriving from a search engine, to avoid detection. As a logged-in administrator you rarely notice anything. That makes redirects one of the hardest types to spot on your own, and one of the most damaging to trust.

Cryptominers and phishing

A cryptominer hijacks your server power to mine cryptocurrency, making the site slow and driving up resource usage — sometimes so much that the host suspends you. Phishing kits put fake login pages (for banks, payment services) on your server to steal other people’s credentials. Both turn your site into a tool in someone else’s crime — with your name on it.

Why they often coexist

An infected site rarely has just one type. The attacker starts with a backdoor and then layers on whatever makes money — spam, redirects, mining, phishing. Often the access is even resold, so several different actors exploit the same site at once. That’s why removing what you see isn’t enough; you have to find the entry point too, or the site is re-infected within days.

What you see is rarely the whole infection. The backdoor you don’t see is the one that counts.

— Kepler Security Scan

The right cleanup takes the whole chain

Our WordPress cleanup scans files, database and core files to find every part — not just the visible symptom — and leaves a report of what was found and how it got in. Want to reduce the risk of it happening at all? Run Managed WordPress hosting, where monitored updates and per-site isolation close the entry points before they’re exploited.

Bygg på ett moln du faktiskt äger.

Ingen bindningstid. En körande VM innan du betalar en krona.