Phishing Scammers Benefit from Shady SEO Practices to Rank Better Than Legitimate Domains

Stu Sjouwerman | May 24, 2022

Phishing Scammers Benefit from Shady SEO Practices to Rank Better Than Legitimate DomainsSo-called “Black Hat SEO” services have popped up on Dark Web forums bringing advantageous search results to anyone willing to pay a small monthly fee.

According to security vendor Cybersixgill, threat actors are making use of services that exploit illegal SEO tactics using a combination of stuffing keywords, redirecting links from other sites and making use of paid links. Any domain – whether malicious or legitimate – that uses these techniques will eventually be delisted from search engines. But, because threat actors can change domains like the wind changes directions, making temporary use of the beneficial SEO rankings has become so popular that it’s now being offered as a service.

Now you may be thinking these “SEO experts” are playing by the same rules as regular companies – but that’s just not the case. According to Cybersixgill, an example domain for sale had a whopping 177,105 backlinks pointing to it – something not possible for a legitimate organization to accomplish (unless you're one of the Internet’s most popular websites).

The danger in ranking high for specific search terms is it allows threat actors an opportunity to rank for a seemingly benign term – or even something very targeted to a specific company, industry, or area of research – that would make someone within an organization visit a malicious website and click on malicious links or download malicious files.

Good cyber hygiene best practices taught by Security Awareness Training involve only visiting known-safe websites (whether that’s based on the website being known to the user or because a security solution that scrutinizes domains and/or websites says it is. Be sure your users know about this problem; otherwise they may find out next time they run a search.

Topics: Phishing

Access the World’s Largest Security Awareness Library

Explore over 1,000 interactive modules, videos, and games designed to sharpen user instincts and secure AI interactions. Get instant access to our Free Training Preview and find the perfect content to fortify your security culture.

Get Your Free Training Preview

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.