Short Story About an Illegal Backlinking Method

Daniel from Linxact

Senior Member
Joined
Nov 3, 2016
Messages
852
Reaction score
363
Hi members of BHW,
I wanted to share a short story about an illegal backlinking method. At the end, I'm asking you a question. I would appreciate any answer! Enjoy!

I did a backlink profile analysis (hidden and common backlinks) of a competitor domain for a client recently and noticed something interesting. The competitor domain I analyzed has a huge amount of backlinks that originate from authority websites that have nothing to do with the topic of the competitor domain. That made me suspicious.
I pulled all common backlink data out of the Majestic bulk checker as a CSV file (~500 Megabytes), split it in 9 CSV files with 100k rows each except the last one and filtered each CSV file by TF10+. Then I merged all the CSV files back together and sorted all rows by TF descending. Now I had all the data set up to look into it in more detail. I did a short break and made some tea. After a sip, I copied the top few hundred backlink URLs into the Bulk URL Opener Firefox plugin and pressed on "Open Links". Then I opened the first tab. It showed me an interesting TF60 domain of an English book author, but I could not find that specific backlink. That just reinforced my suspicion.
It was time to open the HTML source code and search for that competitor domain in there. Result: no elements found. Weird. Then I tried again by searching for the anchor text included in the Majestic CSV export, and strike! The HTML source code includes a dozen of bit.ly shortened links with highly relevant anchor texts. One of the bit.ly links forwarded me to the competitor domain. The CSS code made sure that those links would be visually hidden from any regular visitor and the website owner. So with this finding it was clear that the poor author's website had been hacked and injected with visually hidden backlinks (!= hidden backlinks which block ahrefs, Majestic, Moz, SEMrush and co).
The funny part about it is that the author's website had probably been hacked twice. Why, you may ask. I checked that website again with different user agents (shoutout to the Firefox plugin User-Agent Switcher). All user agents showed me the same website, with one exception: Using Googlebot would activate a completely different website that was completely filled with Chinese content. So those injected backlinks had no effect anymore. Poor competitor.
Continuing with my work resulted in few hundred more high TF injected backlinks of hacked websites. Mostly websites using the WordPress CMS. I reported all the bit.ly links I could find, but I'm not sure if this will result in something. Another option would be to contact those website owners. I will wait for my client to decide on that.
My question to you is: Why do those hackers inject bit.ly links? It makes sense to me to use a forwarding URL as a link instead of a raw link to be able to change the link target even after losing access to a hacked website, but why depend on bit.ly? You could just use a custom domain with a 301 redirect for that. Do they want to prevent an exposure because of outbound link checking plugins / software? I doubt it because a bit.ly link is suspicious as hell on such authority websites. To me, it looks like those websites have been hacked by a backlinking service that rents out those backlinks to their customers. If someone knows such a service, please send me a dm with the name or URL. I'm very curious how they present themselves and what they exactly offer. Do they lie to their clients, or do they directly and openly promote injected backlinks? I assume that those services are not public know, though.

Let me know what you think. Thank you for reading and have a nice day!

Sincerely,
The Data Scientist
 
Last edited:
I don't know the answers to your questions, but that's a really interesting find.

Surely if you kept an eye on your outbound links for your domain, you should notice a considerable spike - in tools like ahrefs for instance.

Interesting on the user-agent switch as well, I'd never heard of anything like that and if the website owner wasn't SEO savvy, they'd never notice - which I assume is the point. Smart.
 
I think this method is old as SEO.
Every site - even launched couple of minutes ago - has constantly hacking attempts.
All internet is scanned by hackers constantly to find some vulnerabilities.
 
I don't know the answers to your questions, but that's a really interesting find.

Surely if you kept an eye on your outbound links for your domain, you should notice a considerable spike - in tools like ahrefs for instance.

Interesting on the user-agent switch as well, I'd never heard of anything like that and if the website owner wasn't SEO savvy, they'd never notice - which I assume is the point. Smart.

I'm pleased, that you find it interesting! Ahrefs would definitely be an option to detect this. I'm sure that there are many plugins and tools that would detect this, but as you said those webmasters are probably not SEO savvy.

I think this method is old as SEO.
Every site - even launched couple of minutes ago - has constantly hacking attempts.
All internet is scanned by hackers constantly to find some vulnerabilities.

It probably is, but I was surprised about the massive scale of injected backlinks on websites with strong backlink profiles.

Sincerely,
The Data Scientist
 
Thanks for this interesting insight! Those guys are Black Hat hackers and SEOs, haha.
 
That's just SAPE links.
They probably use bit.ly as tier 1 links protection cause sometimes those links are toxic

Interesting take. If that should be true, I'm sure that the website owners still do not know that those links are placed on their website. Why would those backlinks be visually hidden with CSS? Are hacked websites on Sape a thing?

How would you determine if a Sape backlink is toxic after having tons of them pointing to your website?

Sincerely,
The Data Scientist
 
could be SAPE yes, or just someone out of the 100s of people who do this kind of stuff themselfs.
placing hidden links on hacked sites is a very old tactic and there are multiple ways to hide, but like you noticed most do simple UA cloaking.
it works, but never understood why some people take the risk of hacking for just backlinks.. if you go down that road, you could make money in a better way lol
 
These types of backlinks are not new these are often also referred to as Exploit backlinks by backlink sellers.
Funniest thing is back in the day when I was novice to SEO I was told by an SEO expert that apart from the general Directory submission links they can provide very good quality Exploit backlinks.
When I asked what are these he replied saying PHP errors allow use to insert you links on hard sites.
These links used to work great for Parasites, CPA and churn & burn projects.
I still use them for T2 links foe Web 2.0 embeds for YT videos.
 
could be SAPE yes, or just someone out of the 100s of people who do this kind of stuff themselfs.
placing hidden links on hacked sites is a very old tactic and there are multiple ways to hide, but like you noticed most do simple UA cloaking.
it works, but never understood why some people take the risk of hacking for just backlinks.. if you go down that road, you could make money in a better way lol

Most websites did not cloak anything. Those links were just hidden with CSS code. The author website was cloaked by another entity that had nothing to do with those links. I think that link cloaking is easily detectable by the Google crawler. It is the worst enemy to Google.

These types of backlinks are not new these are often also referred to as Exploit backlinks by backlink sellers.
Funniest thing is back in the day when I was novice to SEO I was told by an SEO expert that apart from the general Directory submission links they can provide very good quality Exploit backlinks.
When I asked what are these he replied saying PHP errors allow use to insert you links on hard sites.
These links used to work great for Parasites, CPA and churn & burn projects.
I still use them for T2 links foe Web 2.0 embeds for YT videos.

I have never heard the term "exploit backlinks" before. Interesting. I have to mention that this competitor I had to analyze is probably generating a six to seven-figure revenue each month. That competitor is getting some serious backlinks.

Injected links have been going on for a long time.
Let's be honest, that is a good portion of niche edit sellers. ;)

You really have to watch where you buy your links.

Thanks for the hint!
 
Back in 2017 there was a thread discussed by famous @Asif A Khan LONDON (it could be anyone else but i asked asif couple of question about this issue) about this hidden injected link with sample too.
So, this hidden inject stuff bit old & used by some seo'er for some long time.

As someone mentioned SAPE, I saw most of them are visible links only a very few of them are hidden. (I still use them as T2)
 
Back
Top