# Joomla SEO Spam Injector — Obfuscated PHP Backdoor Hijacking Site Visitors (php.spam-seo.joomla-injector.002)

> Active mass-compromise campaign against outdated Joomla (<5.X) installations deploys a heavily obfuscated PHP loader at the top of index.php. On every page load the backdoor exfiltrates $_SERVER data to C2 cdn.erpsaz.com (primary) or cdn.saholerp.com (fallback) and selects one of three cloaking modes — silent visitor redirect, raw HTML injection, or fake XML-sitemap / HTML served to search crawlers — enabling large-scale SEO poisoning, visitor hijacking, and reputation damage.

- **Published:** 2026-04-17T12:00:00Z
- **Last reviewed:** 2026-04-17T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0385
- **ID:** TL-2026-0385
- **Severity:** HIGH (CVSS 8.1)
- **Category:** MALWARE
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 28 (full data via the Threadlinqs MCP server — Purple tier)

## Description

TL-2026-0385 tracks an active Joomla compromise campaign documented by Sucuri on 2026-04-16 (Puja Srivastava). The attacker injects a small, heavily obfuscated PHP loader at the very top of the target site's index.php. The loader is structured across four functions — wffn() (bootstrap decoder), mpjy() (27-entry string lookup table), fotr() (traffic cop / cloaking engine), and joog() (HTTP requester and exfiltrator). All sensitive strings (function names explode, base64_decode, curl_exec, domain fragments, URL components, header names) are fragmented into two-character concatenations (for example 'BASE6' . '4_dec' . 'ODE') and/or stored as a tilde-delimited base64 blob decoded into a 27-index lookup table — defeating naive signature scanners that search for literal sinks or complete base64 strings.

On every page load the backdoor serializes data from the PHP $_SERVER superglobal (HTTP_HOST, REQUEST_URI, HTTP_USER_AGENT, REMOTE_ADDR, etc.), base64-encodes it, and issues a curl_exec() GET to http://cdn.erpsaz.com/admin.php?ua=<encoded_fingerprint>. If the primary returns an empty/non-200 response, the loader retries exactly once against http://cdn.saholerp.com/admin.php (a second flag prevents infinite recursion). A third domain, lashowroom.com, is fully decoded at index 25 of the string table but is never referenced by any URL-constructing index call — present as a decoy to waste analyst time.

The fotr() function then branches on the C2 response: (Mode 1) if the body starts with 'http' the loader issues header('Location: ' . $body) and exit()s, silently redirecting the visitor to an attacker-chosen URL; (Mode 2) if the body starts with '##', the prefix is stripped via substr($body, 2) and the remainder is echoed directly into the page, injecting arbitrary spam HTML (e.g. the spam product links reported by the original victim); (Mode 3) if the response length exceeds 90 characters and contains '</urlset>' the loader sets Content-type:text/xml and returns the body as a fake XML sitemap, otherwise if the body contains '<html' it serves the raw HTML — both modes designed to cloak responses to search-engine crawlers and inject keyword-stuffed pages for SEO poisoning.

Because all directives are delivered remotely and the local file footprint is a single obfuscated block, defenders often miss the infection during casual inspection. The same site can be redirecting end users one hour and feeding Google a fake sitemap the next — fully controlled by the C2 operator. This dynamic control makes the infection long-lived and hard to correlate with any one visible symptom. Root cause in every Sucuri case studied has been exploitation of known, patched vulnerabilities in Joomla core or third-party extensions on installations running branches older than 5.X (which is end-of-life).

C2 infrastructure resolves to 91.239.78.37 (AS6698 VIRTUALSYSTEMS, RIPE, Poland/Ukraine) for cdn.erpsaz.com and 195.26.86.16 (AS43641 SOLLUTIUM-NL, RIPE, Ukraine/Poland) for cdn.saholerp.com. Both parent zones (erpsaz.com, saholerp.com) use Cloudflare nameservers, masking origin at the DNS layer but revealing authoritative zones directly on the sub-CDN hostnames. Sucuri tracks the family under signature php.spam-seo.joomla-injector.002 (original signature lineage dates to 2019; this 2026 variant is the first with the fragmented-string + tilde-delimited-table obfuscation pattern).

Impact is financial and reputational: compromised domains push traffic and link equity to attacker-promoted products, search engines demote or de-index cloaked pages, browsers may flag the site via Safe Browsing, and ad fraud downstream is common. The backdoor does not itself include the spam content — it is a pure remote loader, so removal requires deleting the injected block from index.php, resetting all admin credentials, and completing a full integrity scan of every PHP file on the host to locate any secondary implants.

## MITRE ATT&CK

- T1595 Active Scanning
- T1583 Acquire Infrastructure
- T1608 Stage Capabilities
- T1190 Exploit Public-Facing Application
- T1189 Drive-by Compromise
- T1059 Command and Scripting Interpreter
- T1505 Server Software Component
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1036 Masquerading
- T1082 System Information Discovery
- T1071 Application Layer Protocol
- T1132 Data Encoding
- T1568 Dynamic Resolution
- T1102 Web Service
- T1008 Fallback Channels
- T1496 Resource Hijacking
- T1491 Defacement

## Sources

- [Sucuri Blog: Joomla SEO Spam Injector — Obfuscated PHP Backdoor Hijacking Site Visitors](https://blog.sucuri.net/2026/04/joomla-seo-spam-injector-obfuscated-php-backdoor-hijacking-site-visitors.html)
- [Sucuri Labs Signature: php.spam-seo.joomla-injector.002](https://labs.sucuri.net/signatures/malwares/php-spam-seo-joomla-injector-002/)
- [Joomla! 5.X Downloads and Upgrade Information](https://www.joomla.org/download.html)
- [Joomla! Security Announcements](https://developer.joomla.org/security-centre.html)
- [MITRE ATT&CK: Server Software Component — Web Shell (T1505.003)](https://attack.mitre.org/techniques/T1505/003/)
- [MITRE ATT&CK: Obfuscated Files or Information — Encrypted/Encoded File (T1027.013)](https://attack.mitre.org/techniques/T1027/013/)
- [MITRE ATT&CK: Obfuscated Files or Information — Command Obfuscation (T1027.010)](https://attack.mitre.org/techniques/T1027/010/)
- [MITRE ATT&CK: Application Layer Protocol — Web Protocols (T1071.001)](https://attack.mitre.org/techniques/T1071/001/)
- [MITRE ATT&CK: Data Encoding — Standard Encoding (T1132.001)](https://attack.mitre.org/techniques/T1132/001/)
- [MITRE ATT&CK: Resource Hijacking (T1496)](https://attack.mitre.org/techniques/T1496/)
- [MITRE ATT&CK: Exploit Public-Facing Application (T1190)](https://attack.mitre.org/techniques/T1190/)
- [CWE-506: Embedded Malicious Code](https://cwe.mitre.org/data/definitions/506.html)
- [CWE-94: Improper Control of Generation of Code (Code Injection)](https://cwe.mitre.org/data/definitions/94.html)
- [CWE-601: URL Redirection to Untrusted Site ('Open Redirect')](https://cwe.mitre.org/data/definitions/601.html)
- [Google Search Central: Hacked sites — cloaking](https://developers.google.com/search/docs/monitor-debug/security/hacked)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0385
