What happened, in one table
| Client | Decoruss, interior design and decoration, Lucknow (decoruss.com). A second site on the same hosting account, lucknowdeco.com, was checked and cleaned as well. |
|---|---|
| How it was found | The owner searched for website malware removal, ran the free Apex Influence surface scan, read the result and sent a deeper-check request at 03:50 IST on 7 October 2026. |
| What the scan flagged | Script and HTML tags inside robots.txt, and 1xbet, 1win and casino names in the post sitemap. The Googlebot copy of the homepage carried a casino title the visitor copy did not. |
| Compromised since | At least 6 August 2026, from file dates and the earliest spam post. |
| Cleaned and handed over | 8 October 2026, with a written log of every change and a 30-day quarantine of every removed file. |
| Verified from outside | Same page served to a phone, Googlebot and Bingbot. No injected code. Plain robots.txt. Zero spam URLs in the sitemap. Cloak page and doorway folder gone. |
What Google saw, and what visitors saw, on the same day
This is the part that makes a cloaked hack dangerous. The site passed every eyeball test. The owner, the team and any developer opening decoruss.com in a browser saw the real portfolio. Only requests that identified themselves as Googlebot were handed a casino page. The left image is the homepage exactly as it was served to Googlebot on 7 October 2026, captured during the assessment. The right image is the live site after the cleanup.
Check it yourself: visit the live site · run the same free scan on any domain
A self-repairing kit, not a single bad file
The visible symptom was one hidden plugin. The reason it would have survived a normal cleanup was everything built around it:
- A must-use plugin that checked the user agent, served a casino page to Googlebot, and appended a hidden block plus three scripts to every response, including robots.txt.
- An hourly scheduled job that reinstalled the plugin if anyone removed it.
- A 15 MB base64 copy of the whole kit stored inside the WordPress options table, so the cron job always had something to reinstall from.
- 35 copies of the kit's files in hidden folders, three fake plugin folders, two web shells and eleven fake WordPress core files.
- A rewrite rule that sent Googlebot to a static casino page, and a folder of ten casino doorway pages.
- Three planted administrator accounts, one spam author with 34 gambling posts hidden from the blog listing, and 3,656 spam comments.
- A Google Search Console verification file placed by the intruder, which would have given them a view of the site's search data.
The second site on the same hosting account, lucknowdeco.com, had two disguised must-use plugins dated 14 September. One hid an administrator named "advisor" from every user list. The other was a backdoor that answered to a secret web address. The hidden administrator had been created in the same minute as the files.
Why the order matters more than the tools
Delete the plugin first and the cron job puts it back within the hour. Delete the cron job and the database seed is still there for the next entry. The sequence that held:
- Backup and evidence first. A fresh hosting backup, and the Googlebot copy of the homepage saved before anything was touched.
- Stop the re-installer. The hourly cron events removed, then the database seed rows deleted.
- Remove the planted accounts. Three administrators and the spam author deleted, with their content reassigned so nothing legitimate was lost. On lucknowdeco.com the hidden "advisor" administrator and a passwordless temporary-login account were removed.
- Quarantine, never delete. Every malicious file was moved to a folder outside the web root and kept for 30 days, so any file can be restored if a cleanup step turns out to be wrong.
- Replace the core. WordPress core re-downloaded and every file verified against the official checksums. The fake core files failed that check and were quarantined.
- Rotate everything the intruder may hold. Both admin login names changed, passwords reset, database password rotated, security salts rotated on both sites so every existing session was logged out.
- Close the doors. Wordfence with five-strike lockouts and email alerts, PHP execution blocked inside uploads, XML-RPC blocked, dashboard file editor off, registration closed, version files removed, plugins updated, 3,656 spam comments removed.
- Verify from outside, not from the dashboard. A hacked site will tell you it is clean from the inside. The checks below were run from a separate server.
Verified from outside on 8 October 2026
| Check | decoruss.com | lucknowdeco.com |
|---|---|---|
| Same page to a phone, Googlebot and Bingbot | yes | yes |
| Injected code on the homepage | none | none |
| robots.txt | plain | plain |
| Spam URLs in the sitemap | 0 | 0 |
| Cloak page and doorway folder | gone (404) | never present |
| Backdoor address | gone | gone |
| XML-RPC | blocked | blocked |
| PHP inside uploads | blocked | blocked |
| Apex surface scan | nothing alarming | nothing alarming |
Rechecks continue daily for a week and again at two weeks. A handover note with the remaining owner-side items (two-factor login, PHP 8.3, Search Console review request) was given to the client.
Shared publicly on LinkedIn, with the client's agreement
The recovery was written up on LinkedIn as a checklist for other interior design and fit-out firms, with Shaurya Pratap Singh and the Decoruss page tagged. Both the founder and the company page reacted to the post, and Decoruss accepted the collaboration tag. The post and the reactions are below as they appear on LinkedIn.
Three checks you can run this week
Design studios and fit-out contractors tend to run the same WordPress themes, page builders and plugins. The portfolio looks premium; the locks are often the defaults. None of these checks needs a developer.
- Compare what Googlebot sees with what you see. The free surface scan fetches your homepage twice, once as a visitor and once as Googlebot, and compares the titles, headings and outbound links. It also reads your robots.txt and sitemap.
- Name every administrator. Open Users in your WordPress dashboard. If there is an administrator you cannot name, it is not yours.
- Read your own sitemap. Open yoursite.com/sitemap.xml and look for pages you never wrote. Casino, pharma and loan spam shows up there first.
If any of the three fails, do not delete anything yet. Take a backup, keep the evidence, and ask for a deeper check. Our other public recovery, Edge Glaze in June 2026, was a different kit with the same lesson: the file you can see is rarely the whole infection.
What is a cloaked WordPress hack?
A cloaked hack serves one page to search engines and another to people. On decoruss.com, Googlebot was shown a casino page while every human visitor saw the real interior design site. It is also called SEO spam, the casino hack or the Japanese keyword hack, and it is in the same family as the pharma hack and the redirect hack.
How was the Decoruss hack found?
The owner searched for website malware removal, ran the free Apex Influence surface scan on decoruss.com, read the result and asked for a deeper check the same night. The scan flagged script tags inside robots.txt and gambling names in the sitemap. The deeper check then compared the Googlebot copy of the homepage with the visitor copy.
Why did the hack keep coming back before the cleanup?
The kit had an hourly cron job that reinstalled it, a 15 MB copy of itself stored inside the WordPress database, and 35 hidden copies of its files. Deleting the visible plugin alone was undone within the hour. The order that holds is: remove the cron job, clear the database seed, remove the planted administrators, then clean the files, then verify from outside.
What does Apex Influence charge for a recovery like this?
Recovery is priced per case after a free check. The size of the site, the type of infection and whether a second site shares the hosting account all change the work, so a fixed quote is given before any work begins. Nothing is deleted during a cleanup; every file is quarantined for 30 days so it can be restored.
How can an interior design or fit-out company check its own website?
Three checks. First, compare what Googlebot sees with what you see in your browser; the free scan at apexinfluence.in/scan-website-for-malware does this. Second, open Users in WordPress and name every administrator. Third, open your sitemap and look for pages you never wrote.
Is your site showing Google something you cannot see?
Run the free surface scan first. If it flags something, or you already know the site is hacked, leave your details below. We confirm what is wrong, then give you a fixed quote before any work begins. No fixed-time or guaranteed-clean promises; every infection is different and we say what your site needs.
Prefer to talk now? Call +91 97402 00860. Your details are used only to help with your site.
Once you are clean, keep it that way
Decoruss had no monitoring, which is why a hack planted in August was still running in October. Our Secure plan keeps watch at Rs 6,000 (about $72) per month: ongoing monitoring, regular backups, and priority cleanup if anything is ever flagged again.