Joomla SEO Spam Injector: Obfuscated PHP Backdoor Hijacking Site Visitors

Reported 17 Apr 2026 by otx · Severity: medium

A compromised Joomla website displayed suspicious product links unrelated to the business. Investigation revealed heavily obfuscated PHP code injected at the top of index.php that contacted external command-and-control servers to receive instructions and manipulate content. The m