Daniel from Linxact
Senior Member
- Nov 3, 2016
- 852
- 363
Hi members of BHW,
I wanted to share a short story about an illegal backlinking method. At the end, I'm asking you a question. I would appreciate any answer! Enjoy!
I did a backlink profile analysis (hidden and common backlinks) of a competitor domain for a client recently and noticed something interesting. The competitor domain I analyzed has a huge amount of backlinks that originate from authority websites that have nothing to do with the topic of the competitor domain. That made me suspicious.
I pulled all common backlink data out of the Majestic bulk checker as a CSV file (~500 Megabytes), split it in 9 CSV files with 100k rows each except the last one and filtered each CSV file by TF10+. Then I merged all the CSV files back together and sorted all rows by TF descending. Now I had all the data set up to look into it in more detail. I did a short break and made some tea. After a sip, I copied the top few hundred backlink URLs into the Bulk URL Opener Firefox plugin and pressed on "Open Links". Then I opened the first tab. It showed me an interesting TF60 domain of an English book author, but I could not find that specific backlink. That just reinforced my suspicion.
It was time to open the HTML source code and search for that competitor domain in there. Result: no elements found. Weird. Then I tried again by searching for the anchor text included in the Majestic CSV export, and strike! The HTML source code includes a dozen of bit.ly shortened links with highly relevant anchor texts. One of the bit.ly links forwarded me to the competitor domain. The CSS code made sure that those links would be visually hidden from any regular visitor and the website owner. So with this finding it was clear that the poor author's website had been hacked and injected with visually hidden backlinks (!= hidden backlinks which block ahrefs, Majestic, Moz, SEMrush and co).
The funny part about it is that the author's website had probably been hacked twice. Why, you may ask. I checked that website again with different user agents (shoutout to the Firefox plugin User-Agent Switcher). All user agents showed me the same website, with one exception: Using Googlebot would activate a completely different website that was completely filled with Chinese content. So those injected backlinks had no effect anymore. Poor competitor.
Continuing with my work resulted in few hundred more high TF injected backlinks of hacked websites. Mostly websites using the WordPress CMS. I reported all the bit.ly links I could find, but I'm not sure if this will result in something. Another option would be to contact those website owners. I will wait for my client to decide on that.
My question to you is: Why do those hackers inject bit.ly links? It makes sense to me to use a forwarding URL as a link instead of a raw link to be able to change the link target even after losing access to a hacked website, but why depend on bit.ly? You could just use a custom domain with a 301 redirect for that. Do they want to prevent an exposure because of outbound link checking plugins / software? I doubt it because a bit.ly link is suspicious as hell on such authority websites. To me, it looks like those websites have been hacked by a backlinking service that rents out those backlinks to their customers. If someone knows such a service, please send me a dm with the name or URL. I'm very curious how they present themselves and what they exactly offer. Do they lie to their clients, or do they directly and openly promote injected backlinks? I assume that those services are not public know, though.
Let me know what you think. Thank you for reading and have a nice day!
Sincerely,
The Data Scientist
I wanted to share a short story about an illegal backlinking method. At the end, I'm asking you a question. I would appreciate any answer! Enjoy!
I did a backlink profile analysis (hidden and common backlinks) of a competitor domain for a client recently and noticed something interesting. The competitor domain I analyzed has a huge amount of backlinks that originate from authority websites that have nothing to do with the topic of the competitor domain. That made me suspicious.
I pulled all common backlink data out of the Majestic bulk checker as a CSV file (~500 Megabytes), split it in 9 CSV files with 100k rows each except the last one and filtered each CSV file by TF10+. Then I merged all the CSV files back together and sorted all rows by TF descending. Now I had all the data set up to look into it in more detail. I did a short break and made some tea. After a sip, I copied the top few hundred backlink URLs into the Bulk URL Opener Firefox plugin and pressed on "Open Links". Then I opened the first tab. It showed me an interesting TF60 domain of an English book author, but I could not find that specific backlink. That just reinforced my suspicion.
It was time to open the HTML source code and search for that competitor domain in there. Result: no elements found. Weird. Then I tried again by searching for the anchor text included in the Majestic CSV export, and strike! The HTML source code includes a dozen of bit.ly shortened links with highly relevant anchor texts. One of the bit.ly links forwarded me to the competitor domain. The CSS code made sure that those links would be visually hidden from any regular visitor and the website owner. So with this finding it was clear that the poor author's website had been hacked and injected with visually hidden backlinks (!= hidden backlinks which block ahrefs, Majestic, Moz, SEMrush and co).
The funny part about it is that the author's website had probably been hacked twice. Why, you may ask. I checked that website again with different user agents (shoutout to the Firefox plugin User-Agent Switcher). All user agents showed me the same website, with one exception: Using Googlebot would activate a completely different website that was completely filled with Chinese content. So those injected backlinks had no effect anymore. Poor competitor.
Continuing with my work resulted in few hundred more high TF injected backlinks of hacked websites. Mostly websites using the WordPress CMS. I reported all the bit.ly links I could find, but I'm not sure if this will result in something. Another option would be to contact those website owners. I will wait for my client to decide on that.
My question to you is: Why do those hackers inject bit.ly links? It makes sense to me to use a forwarding URL as a link instead of a raw link to be able to change the link target even after losing access to a hacked website, but why depend on bit.ly? You could just use a custom domain with a 301 redirect for that. Do they want to prevent an exposure because of outbound link checking plugins / software? I doubt it because a bit.ly link is suspicious as hell on such authority websites. To me, it looks like those websites have been hacked by a backlinking service that rents out those backlinks to their customers. If someone knows such a service, please send me a dm with the name or URL. I'm very curious how they present themselves and what they exactly offer. Do they lie to their clients, or do they directly and openly promote injected backlinks? I assume that those services are not public know, though.
Let me know what you think. Thank you for reading and have a nice day!
Sincerely,
The Data Scientist
Last edited: