Keeping WordPress websites secure requires constant attention. In a recent case we came across a particularly sneaky type of attack that had been running unnoticed on a client's website for years. This story shows how sophisticated modern hacking techniques are, and why proactive website maintenance is essential.
The hidden threat: what is cloaking malware?
The website we examined showed a strange pattern: Google Search Console was warning about spam content, while visitors noticed nothing unusual. For the owner everything worked fine, the admin area looked flawless and the pages loaded.
This type of attack is called cloaking, and it is one of the most dangerous WordPress security threats. The essence of the method is that the malicious code can tell different types of visitors apart:
- It shows normal users and the site owner the flawless, original content
- It serves search engine bots (such as Googlebot) completely different, spam content
- It shows no errors or anomalies in the admin area
This kind of attack is especially dangerous because it can run for months, even years, without anyone noticing. The client sees nothing suspicious, visitors don't complain, while in the background the site's search engine optimisation and reputation are being damaged all the time.
Discovering the problem: Google Search Console warnings
The infection was first flagged by Google Search Console warnings. Two critical messages came in:
- “Content flagged as spam” : Google detected that the website was serving spam content
- “Cloaking suspected” : the system identified suspicious differences between the content shown to different users
These signals called for an immediate professional investigation. Experience shows that when Google sends warnings like these, the problem is already serious and long-standing.
Results of the in-depth investigation
During a detailed review of the website's file system, we identified several suspicious and clearly infected files. The most shocking discovery was that the infected files were hiding in WordPress's uploads folder, a place that normally only holds uploaded images, videos and documents.
The infected files we found:
eere.htm: an HTML file used to store spam contentroot.htm: more malicious HTML contenthuc.php: a PHP script that ran the cloaking logichuv.php: an additional infected PHP filelicense.txt: a fake licence file that actually contained the cloaker's configuration
Together these files formed a complex system whose job was to load spam content dynamically, segment users, and bypass WordPress's basic security mechanisms.
The most dangerous discovery: a modified functions.php
The investigation revealed that the infected files weren't only in the uploads folder. The biggest problem was caused by a modification to the functions.php file in the site's active theme. This file is the most critical component of a WordPress theme and fundamentally affects how the site works.
The injected code did exactly the following:
- User agent check : it checked the visitor's browser identifier, looking for keywords such as “google”, “googlebot” and “bot”
- IP address check : it compared the visitor's IP address with Google's documented IP ranges
- Content swap : if it identified a Google bot, it immediately loaded the spam HTML files
- Plugin manipulation : it automatically deactivated the cache and minify plugins using the
deactivate_plugins()function
This last point explained the previously inexplicable fact that the site's layout was sometimes “broken”. The infection periodically switched off the performance optimisation plugins the site needed to work properly.
Why are cloaking attacks so hard to spot?
The effectiveness of cloaking malware comes from its invisibility. Several factors help these attacks stay hidden for years:
- No visual change : for the site owner, everything works as usual
- The WordPress admin looks clean : there are no error messages or warnings
- Visitors notice nothing : only search engine bots see the spam content
- Deeply hidden files : the infected files are in places the average user never looks
- Legitimate file names : the file names don't raise suspicion at first glance
According to expert estimates, a well-hidden cloaking infection can go unnoticed for as long as 3 to 5 years, constantly damaging the site's search rankings and reputation.
The likely origin of the infection: a vulnerability in an outdated plugin
The investigation revealed that the site was running an old appointment booking system that the owner had previously insisted on keeping. This was the source of the problem:
- The plugin hadn't received a single update since 2022
- The developers had stopped supporting and maintaining it
- Known security holes were documented in earlier versions of the plugin
- The plugin was still active and running on the site
Abandoned plugins like this are hackers' favourite targets. Automated bots constantly scan websites looking for components with known vulnerabilities. When they find one, running the exploit is child's play:
- The bot identifies the vulnerable plugin
- It exploits the security hole
- It uploads the malicious files
- It embeds the cloaker code into critical system files
- It covers its tracks
This scenario fits the pattern we saw perfectly.
Steps of the clean-up process
Removing the infection completely took careful, multi-step work:
- Identifying infected files : combing through with manual and automated tools
- Cleaning the uploads folder : removing every suspicious .php, .htm and other executable file
- Restoring functions.php : cleaning the theme's critical file or restoring it to its original state
- Checking the root directory : reviewing the PHP files in the root directory
- Database check : looking for suspicious entries and options
- .htaccess check : reviewing the server configuration file
- Full update : updating WordPress core, every plugin and the theme
- Removing unnecessary components : especially outdated, unsupported plugins
- Repeated checks : validating that the clean-up was successful
Throughout the process, the most important thing was completeness. A single infected file or line of code is enough for the attack to come back.
What would have happened if we hadn't noticed in time?
The long-term consequences of cloaking infections can be disastrous:
- Google penalty : the site can be permanently removed from search results
- Loss of traffic : organic visitors disappear completely
- Domain blacklisting : the domain can end up on other sites' spam filters
- Hosting suspension : the provider may suspend the account
- Brand damage : the business name becomes associated with spam pages
- Business losses : lost customers and orders
These problems can sometimes last for weeks or months, even after the infection has been completely removed, until Google re-indexes and re-evaluates the site.
Key lessons
This case teaches several important lessons about WordPress security:
Don't use outdated plugins! If a plugin hasn't been updated for more than 6 to 12 months and the developer doesn't respond, remove it from the site. No feature is worth the security risk.
The uploads folder is not for storing executable code. Any .php or other script file in this folder is an immediate red flag.
Theme files are off limits. functions.php and other critical files should never be modified by hand or by automation unless you know exactly what you are doing.
Cloaking can only be detected by an expert investigation. An everyday user won't notice anything, which is why regular professional website audits are necessary.
Why is ongoing maintenance essential?
WordPress is an excellent content management system, but its security depends entirely on the quality of its maintenance. A professionally maintained website:
- Is updated regularly (WordPress core, plugins, themes)
- Only uses actively supported components
- Is free of unnecessary elements
- Goes through regular security checks
- Is protected by appropriate security measures
A single abandoned, unupdated plugin is enough to infect a website for years without the owner ever noticing the problem, until it's too late.
Summary
This case study shows how sophisticated and invisible modern hacking techniques can be. With cloaking malware, the attack succeeds precisely because normal use shows no sign of the infection.
We successfully removed the infection from the website, and the system is now clean and secure. But the case is a reminder: website security is not a one-off task but an ongoing activity that requires expertise, attention and proactive thinking.
If you feel something isn't right with your website, or you'd like a thorough security audit, contact us. We'll help protect your website and your business from hidden threats.







