Redirect malware

Your website redirects to a casino or betting site

Visitors land on your page and are sent to a gambling, adult or pharma site — often only on mobile, only from Google, or only once per visitor. That is almost always malware, not a hosting glitch.

Free, passive check — no sign-up. Results in about 20 seconds.

Why it only happens sometimes

Redirect malware is built to stay hidden from the site owner. Typical conditions are:

This is why owners often hear about the problem from customers first.

Where the redirect usually lives

How to confirm it from the outside

  1. Open your site in a private window on a phone, from a Google search result, not by typing the address.
  2. Compare what a normal browser and a search-engine crawler receive. A difference is called cloaking and is a strong sign of compromise.
  3. Run our free website security check. It follows redirects, compares the crawler and visitor view and looks for redirect code and injected spam links.

Removing it properly

Deleting the visible script is rarely enough. The attacker usually left a second way back in — a web shell, a rogue admin user or a modified core file — and the redirect returns within days. A proper cleanup:

  1. Takes a backup of the infected state for analysis.
  2. Compares every core, theme and plugin file against a clean original and removes anything that does not belong.
  3. Cleans the database, removes unknown admin users and rotates all passwords, keys and salts.
  4. Finds and closes the entry point — usually an outdated plugin, a reused password or a writable upload directory.
  5. Requests a review from Google if the site was flagged, and monitors for re-infection.
If your site is redirecting right now, every hour costs visitors and search ranking. Google may label it “This site may be hacked” in results.

Frequently asked questions

Is the redirect my hosting company's fault?

Rarely. In most cases the attacker came in through an outdated plugin, theme or a reused password. Shared hosting can make cross-site infections easier, but the fix is still on the site itself.

Will restoring a backup fix it?

Only if the backup predates the infection and you also close the entry point. Otherwise the same vulnerability is exploited again, often within days.

Why do I not see the redirect myself?

Most redirect malware skips logged-in users, repeat visitors and desktop browsers. Test from a phone, in a private window, coming from a Google search result.

Need it fixed?

We clean compromised websites, close the entry point and give you a written report of what we found and changed.