Over the past year we have cleaned this infection out of dozens of websites belonging to businesses across Kerala. The pattern is consistent enough to be worth writing down.
How to tell if you are infected
Search Google for site:yourdomain.com. If you see pages listed in Japanese — or in any language you did not publish — you are infected. This is the most common symptom and the most damaging, because it destroys your rankings for your own terms.
Other signs: your homepage returns a 500 error or a blank page; Search Console reports pages you never created; your site redirects to somewhere unexpected on mobile only; or your host emails you about a malware detection.
What the infection actually does
The campaign backdoors the site's root index.php, drops persistence files into wp-content, and installs what looks like a legitimate plugin with a generic technical-sounding name. It then generates thousands of spam pages targeting Japanese keywords and cloaks them — showing Googlebot the spam and showing you your normal site, which is why owners often do not notice for months.
It reinfects. Cleaning the visible files without finding the persistence mechanism means it comes back within days, usually under a different name.
What to do
1. Do not just delete files. Take a full backup first, including the database. You will need it to compare against.
2. Find every entry point. Check wp-content/plugins and wp-content/mu-plugins for anything you did not install — especially plugins with plausible-but-meaningless names. Check for hidden directories. Check the root index.php against a clean WordPress copy.
3. Clean the database. The injection often writes to the options and posts tables. File cleanup alone is not enough.
4. Rotate every credential. Hosting panel, FTP, database, all WordPress admin accounts. The attacker has had them.
5. Submit removals in Search Console. Use the URL removal tool for the spam pages, then request a review once the site is clean.
6. Harden. Update core, themes and plugins. Delete everything you are not actively using — an inactive plugin is still executable code. Enable automatic core updates. Put a web application firewall in front of the site.
The longer-term answer
Every one of these infections arrived through the plugin ecosystem. If your website is a straightforward business site — services, portfolio, contact, blog — it does not need WordPress, and a custom-built site removes essentially the entire attack surface. We now build almost all client sites that way, and none of them have been touched.
If you suspect your site is infected and you are not sure where to start, send us the domain. We will check it and tell you what we find, whether or not you engage us to clean it.