HTProtect.org
HTProtect HTProtect JOOMLA SECURITY
htprotect.org Вразливості & інструкції з оновлення
Новинка htprotect.app - Централізоване керування кількома сайтами на Joomla
Emergency help

Japanese Keyword Hack: spotting Japanese pages on your site

Japanese text in your own Google results, pages you never created - and nothing to see when you visit your site. That combination has a name.

Do not trust what you see yourself
Google is blunt here: attackers try to make you believe a page is gone or already fixed when it is not - they hide the content from you. The URL Inspection tool in Search Console is what settles it; it shows you the hidden content underneath.

What the hack does

Google describes the pattern like this: masses of new pages appear, filled with automatically generated Japanese text, placed in folders whose names look random - Google gives the example of an address in the form example.com/ltjmnjp/341.html. The pages earn money through affiliate links to shops selling counterfeit brand goods. Your domain does the ranking work; someone else takes the revenue.

What this has to do with Joomla

The hack is not tied to one system. Sucuri notes it can affect any site, naming WordPress, Drupal, Joomla and Magento. Google is more specific in its Search Console help: under Hacked: Content injection it lists exploiting a vulnerability in the software running the site as one of the typical ways in, and names an older, insecure version of Drupal, Joomla! or WordPress as the example. In April 2026 Sucuri published a Joomla case in detail: heavily obfuscated PHP code sat at the very top of the site’s index.php and worked as a remote control - it contacted an external server, reported details about the site and let the answer decide what visitors were served. The attacker could change the behaviour at any time without touching the files again.

Six checks you can run yourself

  1. Search for your own domain with site:

    Type site:your-domain.com into a normal Google search. You see what Google has indexed for you - planted pages included.

  2. Open the Security issues report in Search Console

    It covers hacked content, meaning anything placed on your site without your permission.

  3. Check who owns the property

    Google names this as a typical sign: with this hack the attacker often adds himself as an owner of your Search Console property, and, in Google’s own words, to increase profits by manipulating your settings such as geotargeting or sitemaps. Google is blunt about it: if you receive a notification that someone you do not know has verified your site in Search Console, there is a strong possibility that it has been hacked.

  4. Look at the page indexing report

    A clear rise in the number of indexed pages, without you publishing anything new, fits the pattern - the hack creates pages in bulk.

  5. Look at the performance report

    Filter by query. Japanese or other foreign-language search terms that have nothing to do with your business are a plain sign that you are being found for someone else’s content.

  6. Check your sitemaps and robots.txt

    See the section below - and note that a sitemap entry on its own is not evidence of anything.

One Joomla detail worth knowing

The robots.txt that Joomla ships contains no Sitemap: line at all - it consists of a comment block, one User-agent line and fifteen Disallow lines. So if your robots.txt names a sitemap, that line came from an extension, from your own edit, or from someone else. Be careful with this signal: a Sitemap line is completely normal and harmless, many SEO extensions add one. It only deserves attention if nobody can explain where it came from. Checking takes ten seconds - open your-domain.com/robots.txt in a browser.

Getting rid of it

The order matters more than the speed. Close the way in first, otherwise the pages simply come back. Then remove what was planted. Only then turn to Google: the Security issues report is also where you ask for a review once the site is clean. Check your sitemaps as well - Google notes that attackers often modify an existing sitemap or add new ones so their addresses get indexed faster.

Cleaning up is only half the job
As long as the way in stays open, the same thing happens again within days. Update Joomla and every extension, and check the official Vulnerable Extensions List for what you have installed.

Sources & further reading

Пріоритет завжди мають офіційні дані відповідного розробника. Ця сторінка нейтрально узагальнює загальнодоступну інформацію.