Home › Website Malware Removal › Decoruss case study

Case study · WordPress · Cloaked casino hack · October 2026

Decoruss: a Lucknow interior design studio's website was showing Google a casino. Here is how it was found, removed and verified.

Decoruss is an interior design and decoration company in Lucknow, Uttar Pradesh, in business since 2010. In October 2026 its WordPress site looked normal to every visitor and to its own team, while Googlebot was being served a casino page from the same address. The owner, Shaurya Pratap Singh, found it himself through a free scan and asked for a deeper check the same night. This page records what was inside the site, the order in which it was removed, how it was verified from outside, and what the owner said afterwards. Shared with the client's agreement.

Run the free scan on your site   Ask for a deeper check

Client: Decoruss, Lucknow Platform: WordPress on shared hosting Request to handover: 7 to 8 October 2026
The short version

What happened, in one table

ClientDecoruss, interior design and decoration, Lucknow (decoruss.com). A second site on the same hosting account, lucknowdeco.com, was checked and cleaned as well.
How it was foundThe owner searched for website malware removal, ran the free Apex Influence surface scan, read the result and sent a deeper-check request at 03:50 IST on 7 October 2026.
What the scan flaggedScript and HTML tags inside robots.txt, and 1xbet, 1win and casino names in the post sitemap. The Googlebot copy of the homepage carried a casino title the visitor copy did not.
Compromised sinceAt least 6 August 2026, from file dates and the earliest spam post.
Cleaned and handed over8 October 2026, with a written log of every change and a 30-day quarantine of every removed file.
Verified from outsideSame page served to a phone, Googlebot and Bingbot. No injected code. Plain robots.txt. Zero spam URLs in the sitemap. Cloak page and doorway folder gone.
Google vs visitors

What Google saw, and what visitors saw, on the same day

This is the part that makes a cloaked hack dangerous. The site passed every eyeball test. The owner, the team and any developer opening decoruss.com in a browser saw the real portfolio. Only requests that identified themselves as Googlebot were handed a casino page. The left image is the homepage exactly as it was served to Googlebot on 7 October 2026, captured during the assessment. The right image is the live site after the cleanup.

decoruss.com as Googlebot
decoruss.com homepage as served to Googlebot on 7 October 2026: a casino login page instead of the interior design site Hacked, Googlebot view
Before · what Google was indexing, 7 October 2026
decoruss.com
decoruss.com homepage clean after the Apex Influence recovery, October 2026 Recovered ✓
After · the same page to Google, Bing and every visitor

Check it yourself: visit the live site · run the same free scan on any domain

What was inside

A self-repairing kit, not a single bad file

The visible symptom was one hidden plugin. The reason it would have survived a normal cleanup was everything built around it:

The second site on the same hosting account, lucknowdeco.com, had two disguised must-use plugins dated 14 September. One hid an administrator named "advisor" from every user list. The other was a backdoor that answered to a secret web address. The hidden administrator had been created in the same minute as the files.

The order of work

Why the order matters more than the tools

Delete the plugin first and the cron job puts it back within the hour. Delete the cron job and the database seed is still there for the next entry. The sequence that held:

  1. Backup and evidence first. A fresh hosting backup, and the Googlebot copy of the homepage saved before anything was touched.
  2. Stop the re-installer. The hourly cron events removed, then the database seed rows deleted.
  3. Remove the planted accounts. Three administrators and the spam author deleted, with their content reassigned so nothing legitimate was lost. On lucknowdeco.com the hidden "advisor" administrator and a passwordless temporary-login account were removed.
  4. Quarantine, never delete. Every malicious file was moved to a folder outside the web root and kept for 30 days, so any file can be restored if a cleanup step turns out to be wrong.
  5. Replace the core. WordPress core re-downloaded and every file verified against the official checksums. The fake core files failed that check and were quarantined.
  6. Rotate everything the intruder may hold. Both admin login names changed, passwords reset, database password rotated, security salts rotated on both sites so every existing session was logged out.
  7. Close the doors. Wordfence with five-strike lockouts and email alerts, PHP execution blocked inside uploads, XML-RPC blocked, dashboard file editor off, registration closed, version files removed, plugins updated, 3,656 spam comments removed.
  8. Verify from outside, not from the dashboard. A hacked site will tell you it is clean from the inside. The checks below were run from a separate server.
Verification

Verified from outside on 8 October 2026

Checkdecoruss.comlucknowdeco.com
Same page to a phone, Googlebot and Bingbotyesyes
Injected code on the homepagenonenone
robots.txtplainplain
Spam URLs in the sitemap00
Cloak page and doorway foldergone (404)never present
Backdoor addressgonegone
XML-RPCblockedblocked
PHP inside uploadsblockedblocked
Apex surface scannothing alarmingnothing alarming

Rechecks continue daily for a week and again at two weeks. A handover note with the remaining owner-side items (two-factor login, PHP 8.3, Search Console review request) was given to the client.

What the client said

Shared publicly on LinkedIn, with the client's agreement

The recovery was written up on LinkedIn as a checklist for other interior design and fit-out firms, with Shaurya Pratap Singh and the Decoruss page tagged. Both the founder and the company page reacted to the post, and Decoruss accepted the collaboration tag. The post and the reactions are below as they appear on LinkedIn.

LinkedIn reactions on the Decoruss recovery post, showing Shaurya Pratap Singh, founder of Decoruss, and the Decoruss company page
Reactions on the post, 10 October 2026: the Decoruss founder and the Decoruss company page. Open the post on LinkedIn
For interior design and fit-out firms

Three checks you can run this week

Design studios and fit-out contractors tend to run the same WordPress themes, page builders and plugins. The portfolio looks premium; the locks are often the defaults. None of these checks needs a developer.

  1. Compare what Googlebot sees with what you see. The free surface scan fetches your homepage twice, once as a visitor and once as Googlebot, and compares the titles, headings and outbound links. It also reads your robots.txt and sitemap.
  2. Name every administrator. Open Users in your WordPress dashboard. If there is an administrator you cannot name, it is not yours.
  3. Read your own sitemap. Open yoursite.com/sitemap.xml and look for pages you never wrote. Casino, pharma and loan spam shows up there first.

If any of the three fails, do not delete anything yet. Take a backup, keep the evidence, and ask for a deeper check. Our other public recovery, Edge Glaze in June 2026, was a different kit with the same lesson: the file you can see is rarely the whole infection.

Questions
What is a cloaked WordPress hack?

A cloaked hack serves one page to search engines and another to people. On decoruss.com, Googlebot was shown a casino page while every human visitor saw the real interior design site. It is also called SEO spam, the casino hack or the Japanese keyword hack, and it is in the same family as the pharma hack and the redirect hack.

How was the Decoruss hack found?

The owner searched for website malware removal, ran the free Apex Influence surface scan on decoruss.com, read the result and asked for a deeper check the same night. The scan flagged script tags inside robots.txt and gambling names in the sitemap. The deeper check then compared the Googlebot copy of the homepage with the visitor copy.

Why did the hack keep coming back before the cleanup?

The kit had an hourly cron job that reinstalled it, a 15 MB copy of itself stored inside the WordPress database, and 35 hidden copies of its files. Deleting the visible plugin alone was undone within the hour. The order that holds is: remove the cron job, clear the database seed, remove the planted administrators, then clean the files, then verify from outside.

What does Apex Influence charge for a recovery like this?

Recovery is priced per case after a free check. The size of the site, the type of infection and whether a second site shares the hosting account all change the work, so a fixed quote is given before any work begins. Nothing is deleted during a cleanup; every file is quarantined for 30 days so it can be restored.

How can an interior design or fit-out company check its own website?

Three checks. First, compare what Googlebot sees with what you see in your browser; the free scan at apexinfluence.in/scan-website-for-malware does this. Second, open Users in WordPress and name every administrator. Third, open your sitemap and look for pages you never wrote.

Deeper check

Is your site showing Google something you cannot see?

Run the free surface scan first. If it flags something, or you already know the site is hacked, leave your details below. We confirm what is wrong, then give you a fixed quote before any work begins. No fixed-time or guaranteed-clean promises; every infection is different and we say what your site needs.

Prefer to talk now? Call +91 97402 00860. Your details are used only to help with your site.

Keep it clean

Once you are clean, keep it that way

Decoruss had no monitoring, which is why a hack planted in August was still running in October. Our Secure plan keeps watch at Rs 6,000 (about $72) per month: ongoing monitoring, regular backups, and priority cleanup if anything is ever flagged again.

Call +91 97402 00860   Ask for a deeper check