Mobile Google Visitors Saw Casino Spam While Everyone Else Saw the Real Site
Normal visitors saw the real homepage. Mobile visitors from Google got a casino AMP page. Here is how I found the trigger.
Normal visitors saw the real homepage. Mobile visitors from Google got a casino AMP page. Here is how I found the trigger.
Wordfence flagged 7 files. The real infection was 30+ backdoors, a WSO web shell, and malware payloads stored inside WordPress database options. Here is the full forensic cleanup.
Describe the mess in two sentences and I will come back with a plan, usually inside two hours.