pharma spam in google — cover illustration
← Blog

Spam links in my site's Google results: pharma, casino and betting

Ivan Pantić

This guide covers pharma spam in google from confirmation through cleanup and prevention.

You type your company name into Google and, under your familiar title, you see results that have nothing to do with you: cheap pills without a prescription, online casinos, betting sites, replica watches or no-check loans. You click through to your site and everything looks normal. No strange pages, no ads, the menu and text are the same as yesterday.

That is exactly why this problem goes unnoticed for so long. Site owners usually find out from a client, from someone who happened to google the company, or when they notice the site has suddenly dropped in search. In security circles this type of attack is called a pharma hack (when it's about medication) or SEO spam injection / casino spam when it promotes gambling and betting. The principle is the same: the attacker uses your domain's reputation so that their pages rank better in Google.

In this article we explain how the attack works, why you don't see it while Google does, how to confirm it in a few minutes, and the order in which it has to be removed so it doesn't come back.

What the pharma hack is and why your site

Section illustration 1

When dealing with pharma spam in google, order matters more than speed.

A pharma hack is an infection in which the attacker injects content onto your site that promotes medication, gambling or other products that legitimate ad networks don't allow. The goal is not to harm you personally but to use your site as a platform.

Why the attacker needs your domain

A brand-new site advertising prescription-free pills is recognised as spam by Google almost immediately and doesn't get shown. A small business site that has existed for years, has normal content and a few natural links, on the other hand, enjoys a certain level of trust from search engines. When an attacker injects hundreds or thousands of spam pages onto such a domain, those pages inherit part of that trust and can appear in search results.

For the attacker it's a cheap way to get traffic. For you it's a serious problem, because over time Google starts treating the whole site as unreliable.

Why it doesn't matter how small the site is

Owners of small sites often assume they aren't interesting to attackers. But these attacks are almost never done by hand. Automated tools scan the internet, look for known vulnerabilities in WordPress plugins and themes, and infect every site where they find one. The size of the site and the nature of the business aren't what matters. What matters is whether there's a hole the tool can get through.

Why you don't see the spam but Google does

Section illustration 2

This is the most confusing part for most owners. You open your site every day, colleagues open it, everything seems fine. So how is Google showing something completely different?

Cloaking: different content for different visitors

The injected code almost always uses a technique called cloaking. Before it serves a page, the code checks who's asking. If the request comes from Google's crawler (Googlebot), it serves spam content with keywords and links. If a regular visitor opens the page, they get the normal site.

Some variants go a step further and check where the visitor came from. If they arrive directly, they see the normal site. If they arrive by clicking a Google result, they're redirected to a spam shop or casino. We covered that form of attack in more detail in Site redirects to another site.

Logged-in administrators often see nothing

Many variants of this code deliberately hide from logged-in administrators. While you're signed in to WordPress, the code behaves completely normally, because it knows you'd be the first to notice. That's why it helps to check the site from a private browser window, when you're not logged in.

Spam pages often don't exist in the menu or in WordPress

The injected pages usually aren't ordinary WordPress pages you'd see under "Pages" or "Posts". Most often they're generated on the fly, based on the URL Google requests. For example, yoursite.com/?p=cialis-no-prescription or yoursite.com/shop/casino-bonus-2026 doesn't exist in your content, but the injected code answers with a spam page when Googlebot visits it.

How to confirm your site is infected

Section illustration 3

There are several checks you can do yourself, without technical knowledge, in about ten minutes.

1. A "site:" search with spam words

Type site:yoursite.com into Google and look at the results. Then try combinations with the words most often abused:

  • site:yoursite.com viagra
  • site:yoursite.com cialis
  • site:yoursite.com casino
  • site:yoursite.com betting
  • site:yoursite.com bonus

If you get results with titles and descriptions you didn't write, the site is almost certainly infected. Pay attention to the number of results, too. A small business site with twenty pages that returns thousands of results for a "site:" search has a problem.

2. Search Console: queries and pages

If you have Google Search Console connected, open the Performance report and look at the list of queries. If you see queries about medication, gambling or products you don't sell, that's a clear sign. Look at the Pages tab as well: strange URLs with parameters or random strings of letters confirm the suspicion.

Check the Page indexing report too. A sudden jump in the number of indexed pages, without you adding content, is one of the most reliable signals.

3. The URL Inspection tool in Search Console

Take one suspicious URL from the search results and check it with the URL Inspection tool. "View crawled page" or "Test live URL" shows what Google actually sees at that address. If you see spam there and a normal page in your own browser, you've confirmed cloaking.

4. Security issues in Search Console

Under Security & Manual Actions, check "Security issues" and "Manual actions". Google sometimes explicitly reports "hacked content" or "spam injected onto the site". If such a warning is active, the site is probably flagged in search as well, which we describe in more detail in Website blacklisted by Google.

5. A free remote check

Our free website malware check compares what the site shows a regular visitor with what it shows a search engine, and checks up to eight internal pages. It can't see files or the database, but it often shows that something is wrong before you dig into the details.

Where this code usually hides

To remove the infection for good, every piece has to be found. A pharma hack is almost never a single file, but several parts that support each other.

Theme and plugin files

The most common place is the active theme's functions.php, but also plugin files, especially plugins that aren't updated. The code is usually obfuscated: long strings of random characters, functions like base64_decode, gzinflate, str_rot13 or eval, and variable names that mean nothing.

WordPress core and root files

Attackers like files owners rarely open: index.php, wp-config.php, wp-settings.php, or files with names that look legitimate, such as wp-cache.php or class-wp-lib.php in a folder where they don't belong.

The database

A large part of pharma infections lives in the database. Typical places are the wp_options table (especially autoloaded options), the wp_posts table with hidden or draft pages, and sometimes separate tables the attacker created. That's why cleaning only the files often doesn't help: the content is regenerated from the database.

.htaccess and server rules

The .htaccess file is often used to redirect visitors coming from Google or to route requests to a hidden file that generates the spam. This file can exist in subfolders too, not only in the site root.

A backdoor for getting back in

Almost every pharma infection comes with at least one backdoor file, a hidden entry point that lets the attacker return even after you remove the spam. How to find such a file is covered in How to find a WordPress backdoor.

How to remove a pharma hack, step by step

Section illustration 4

Use this checklist whenever pharma spam in google shows up again after a partial cleanup.

Order matters. If you skip a step or do it too early, the infection comes back or Google keeps showing spam for months.

Step 1: Make a copy of the current state

Before changing anything, make a full copy of the files and the database, even though they're infected. That copy is for analysis: it helps determine how the attacker got in and whether anything was missed. Don't restore it to the site, just keep it somewhere safe.

Step 2: Change the credentials

Change the passwords for the hosting account, FTP/SFTP, the database and every WordPress administrator. Review the user list and remove accounts you don't recognise. Why simply deleting an unknown account isn't enough is explained in Unknown admin account in WordPress.

Step 3: Replace core, themes and plugins with clean copies

The safest approach is to replace WordPress core, all themes and all plugins with freshly downloaded copies from official sources, the same version or newer. Don't try to "hand-clean" every plugin file. Replacing the whole folder is faster and safer. Plugins you no longer use, and those that haven't been updated in years, should be removed completely.

Step 4: Review files that don't exist in the originals

After the replacement, some files remain that belong to neither core nor plugins: the contents of uploads, files in the site root, cache folders. The uploads folder shouldn't contain PHP files. Treat every .php file in it as suspicious until proven otherwise.

Step 5: Clean the database

Search the database for telltale words (drug names, casino, bonus) and for obfuscated code. Check wp_options for unknown options with long random values, look through wp_posts for hidden pages, and check for tables that belong neither to WordPress nor to your plugins.

Step 6: Check .htaccess and server rules

Compare .htaccess with the standard WordPress version and remove anything you don't understand or didn't add yourself. Check whether there are .htaccess files in subfolders. If your host uses Nginx, the rules live in the server configuration and are usually checked with the host's support.

Step 7: Close the way in

If you don't find out how the attacker got in, the infection comes back. The most common causes are an outdated plugin with a known vulnerability, a pirated (nulled) theme or plugin, a weak admin password or a compromised FTP account. After the cleanup, update everything, enable two-factor authentication for administrators and limit who has access. More detailed measures are in the guide Protect a WordPress site from hacking.

Step 8: Clean up the traces in Google

Once the site is clean, the spam URLs should return an error, and Google needs to revisit them and drop them from the index. This is a separate process with its own rules, and it often takes longer than the cleanup itself. If you skip it, spam results can stay visible for weeks. We describe the whole procedure in Site cleaned, but Google still shows spam pages.

Business impact: why you shouldn't wait

Section illustration 5

Owners often underestimate pharma spam in google until Search Console or clients raise the alarm.

A pharma hack doesn't take the site down or stop it from working. That's why owners sometimes put off reacting. That's a mistake, for several reasons.

Lost search rankings

When Google notices a site serving spam, it usually reduces its visibility and sometimes applies a manual action for hacked content. Rankings for your company name and your services drop, and recovery can take months even after the cleanup.

Damage to your reputation

A client who sees your name next to ads for prescription-free pills or an online casino doesn't think about technical details. They conclude the company isn't serious or can't be trusted. That's especially damaging for law firms, clinics, financial advisers and online shops.

Browser warnings and blocking

If the infection also includes redirects to malicious sites, Google Safe Browsing may flag the site as dangerous. Visitors then see a red warning in Chrome, and some hosting providers and mail services start blocking your domain.

The infection spreads

The backdoor the attacker left behind gets used for other things too: sending spam email, injecting new pages or attacking other sites on the same server. The longer the infection lasts, the bigger the cleanup.

How to protect yourself from a repeat attack

Section illustration 6

After the cleanup, the biggest risk is the same problem returning within a few weeks. It almost always happens for the same reason: the way in wasn't closed or a backdoor was left somewhere. Read more in Infection returns after cleanup.

Basic measures that significantly reduce the risk:

  • Regular updates of core, themes and plugins, ideally once a week.
  • Only original themes and plugins from official sources, no pirated versions.
  • Remove inactive plugins and themes, because even a deactivated plugin can be vulnerable.
  • Strong, unique passwords and two-factor authentication for all administrators.
  • Regular backups stored off the server, with several versions going back.
  • Monitoring: periodically check a site: search and watch Search Console alerts, or use automatic monitoring that reports changes.

Post-cleanup checklist

When you think the job is done, go through this list. If any item fails, the cleanup isn't finished.

  • ☐ A site:yoursite.com search with spam words returns no new results, and the old ones are gradually disappearing.
  • ☐ URL Inspection for several former spam URLs shows the page doesn't exist (a 404 or 410 error), not spam content.
  • ☐ The formerly infected URLs, opened from a private window and by clicking from Google search, don't redirect.
  • ☐ The uploads folder contains no PHP files.
  • ☐ The administrator list contains only people you know, and they all have new passwords and two-factor authentication.
  • ☐ All plugins and themes are updated, and inactive ones are removed.
  • ☐ A review request has been submitted in Search Console if there was a security warning or manual action.
  • ☐ A new, clean backup exists, stored off the server and clearly labelled as the first version after the cleanup.
  • ☐ Monitoring is enabled, or you've scheduled the same check again in a week and in a month.

The last item matters more than it seems. If a backdoor was left behind, the spam usually returns within a few days to a few weeks. A repeat check catches it while the damage is still small.

Next step

pharma spam in google related to Next step

If you've seen spam connected to your site in search results, don't wait for the problem to go away on its own, because it won't. Run a free website check to see what's visible from the internet, and if the result or Search Console confirms the suspicion, get in touch or call +381 65 402 5000. Cleaning a hacked site starts at €100, and urgent cases are handled during the working day.

Questions

Frequent questions

Short answers with this article. If your question is not here, write to us via contact.

Why don't I see the spam when I open my own site?

Because the injected code checks who is opening the page. It shows spam to Google's crawler and a normal site to regular visitors and logged-in administrators. This technique is called cloaking. Check the site with a site:yoursite.com search and the URL Inspection tool in Search Console, which shows what Google actually sees.

Is it enough to delete the spam pages I see in Google?

No. Those pages usually don't exist as real content; the code generates them on the fly. If you don't remove the code, the database entries and the backdoor, the spam reappears, often at new URLs. Removing results from Google only makes sense once the site is clean.

How long does Google keep showing spam results after the cleanup?

It depends on the number of spam URLs and how often Google crawls your site. With smaller infections most results disappear within a few weeks; with large ones it takes longer. You can speed things up with the right server response on the spam URLs, an up-to-date sitemap and the Removals tool in Search Console.

Will Google penalise my site because of the pharma hack?

It can. Google may reduce the site's visibility or apply a manual action for hacked content, and if there are malicious redirects it may show a browser warning. After the cleanup you submit a review request through Search Console, and the penalty is usually lifted once Google confirms the site is clean.

How did the attacker get onto my site in the first place?

Most often through an outdated plugin or theme with a known vulnerability, a pirated (nulled) theme, a weak administrator password or a compromised FTP account. Finding the entry point is a mandatory part of the cleanup, because without it the infection comes back.

Can I clean a pharma hack myself?

If you have WordPress experience, access to the files and database and time for a thorough review, it's partly possible. The problem is that this code hides in several places at once, so it's easy to miss something. If you're not sure, read our comparison DIY malware removal vs professional.

How much does removing a pharma hack cost?

The price depends on the scope of the infection, the size of the site and the urgency. Our Standard Incident package starts at €100, and Emergency Response with priority during the working day at €150. We confirm the exact amount after a short review, before any work begins. Read more about what affects the price in How much does cleaning a hacked site cost.

Not sure if your site has been hacked?

Run a free check. It takes under a minute, with no account and no installation.

Check my site