← All terms

SEO Poisoning

SEO poisoning manipulates search rankings so malicious sites appear as top results, luring users to fake downloads, login pages, and support numbers.

SEO poisoning (search engine optimization poisoning) is the manipulation of search-engine rankings so that attacker-controlled pages appear among the top results for queries people are likely to trust — software downloads, banking logins, IT tools, invoice templates, customer-support numbers. Instead of pushing a lure into the victim's inbox, the attacker waits at the destination the victim was already headed to, which makes the technique unusually effective against users who believe they are being careful by "googling it themselves."

How it works

Attackers combine legitimate SEO tactics with abuse: keyword-stuffed pages, networks of cross-linking sites, compromised high-reputation websites hosting hidden landing pages, and paid search ads that place a malicious result above the organic ones — the point where SEO poisoning overlaps with malvertising. Targets are chosen by intent: a query like "download putty" or "quickbooks support phone number" signals exactly what the victim wants, so the fake result delivers a trojanized installer, a cloned login page, or a fraudulent call center. Campaigns frequently pair the poisoned result with a typosquatted domain that looks plausible at a glance. IT administrators are a prized audience — poisoned results for admin tools have delivered malware loaders that later escalate into full network compromise, a quieter cousin of the watering hole attack.

How to defend against it

  • Change the retrieval habit. Train employees to reach critical services through bookmarks, the company portal, or a password manager's stored URL — never through a fresh search — and to treat "sponsored" download results as hostile by default. Habit-level change is exactly what continuous security awareness training is for.
  • Control the software supply. A managed software catalog or allowlisting removes the reason anyone searches for installers; where that is impractical, publish the official download sources internally.
  • Filter at the network layer with DNS and web filtering that blocks newly registered and known-malicious domains, catching poisoned results even after a click.
  • Fold the scenario into your program: search-delivered lures behave differently from email lures, and the human patterns behind both are what a human risk management program measures and improves.

Related terms

Watering Hole AttackA watering hole attack compromises a website a target group already trusts and visits, infecting visitors instead of approaching them directly.MalvertisingMalvertising is the use of online advertising to spread malware or lead users to phishing pages, often through legitimate ad networks and search ads.TyposquattingTyposquatting registers look-alike domains — misspellings or swapped characters — to catch mistyped URLs and lend fake emails and sites credibility.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo