Spider Pool networks

Boriss

Elite Member
Jr. VIP
Joined
Nov 7, 2009
Messages
2,833
Reaction score
1,429
Found this interesting piece of information on a website.

I’ve been following this method for several months now—one that normally shouldn’t work, yet works extremely well and drives insane amounts of traffic to the sites that use it. The method is black‑hat, it’s heavily combined with parasite SEO to boost the final results, and those who use it risk being harshly penalized by search engines. But they aren’t :)

The sites I constantly monitor that exploit this are still going strong, with fluctuations between 5K and 300K unique visitors per month depending on the scale of the “attack” at any given time, and they rank reasonably well. Behind all of them are always Chinese operators—because it originated there, and probably because in China it’s very cheap to buy such services, with the infrastructure already in place to get everything running as soon as you pay the subscription.

The results of this method are as follows:
  1. The crawler is trapped in an endless series of redirects that lead to pages built solely to receive traffic and “juice,” while in turn generating traffic and juice for other domains or subdomains.
  2. The attacker’s main domain climbs in ranking, reaching good positions on long‑tail keywords.
  3. Domains that fall victim to parasite‑SEO + spider‑pool tactics begin to suffer steep traffic drops, regardless of their authority (you can easily see this happening on some U.S. news publications). This happens for several reasons: they either have an open‑redirect bug that lets attackers create redirects, or an internal search function that’s indexable, or they allow the creation of pages where ******** links point to domains in the spider‑pool. Affected are CMSs, plugins, or simply forums or blogs that leave comments and posts open. Since I’ve been watching this phenomenon I haven’t seen a single compromised site used in combination—just open redirects, spammy pages, subdomains and domains set up to redirect, forums and blogs spammed with links that are often nofollow. Basically, anyone with the technical skills can do this without having to hack sites or servers.
  4. Abused domains A, B and C—unwittingly caught up in the scheme—suffer a drop in their crawl budget allocated by Google, but this only shows up on their legitimate pages. The parasitic pages—where the redirects originate and that belong to the spider pool—get crawled by Google multiple times a day (sometimes hundreds of times a day), whereas the real, normal pages no longer get visited because the entire crawl budget has been consumed by the parasitic pages.
  5. Webmasters of the abused domains take a long time to realize what’s happening, which leads to an unexplained collapse in their traffic. Although all spider‑pool actions appear in Google Search Console in one form or another, they look like random spam that shouldn’t have any effect. The effect only becomes visible when, over a few months, hundreds of thousands of pages that shouldn’t exist appear, and hundreds of thousands of hits on pages returning 404 errors—because those paying for such services often set up their spam campaigns poorly, or use another parasite‑SEO method to index keywords in the victim site’s internal search (a crappy approach that only creates problems for the victims and zero advantage for the spammers).
How it works:

The attacker places on Page A (a high‑authority newspaper’s site) a link that is forced to redirect to Site B (a large retailer’s site), which in turn redirects to Site C (a prestigious university’s site), which then finally forces the crawler onto the attacker’s own site. In the end, the attacker siphons off a little “juice” from each site involved in the redirect chain. This defies every unwritten rule of SEO and shouldn’t work this way—but it does, because there are millions of these actions happening day after day.

Example:
Spammy page with links →
domainA.com/redir.php?out=https://domainb.com/link?u=https://...//anotherattackerdomain.com/internalpage.html
attackersubdomainA/pagewithlinks+sitemapRedirect →
attackersubdomainB/pagewithlinks+sitemapRedirect →
attackersubdomainC/pagewithlinks+sitemapRedirect →
attackermoneysite+sitemapRedirect → infinite redirects

Attackers always use on their domains and subdomains a combination of many external links and sitemaps that force search engines to treat the redirects as legitimate. Very often they also involve expired domains, which they configure to create and delete spammy subdomains on an endless loop.



I know it sounds convoluted—even when you see the entire flow live in front of you—and I’d like to provide clear examples with GSC screenshots, stats, etc., but I can’t share any of that right now without revealing private data. The results are hard to explain because everything that happens contradicts what we know about how Google works, what it penalizes, and what it rewards. In practice, the search engine is so confused by the millions of redirects and spammy link pages that its anti‑spam algorithms lose their intended effect. The fact that victim domains plummet in a few months makes this method useful both for SEO gains and for negative SEO.

The study below explains some of the attack methods and their outcomes, but the method has since been combined with parasite SEO and other rather rudimentary techniques, which together deliver exceptionally good results. You won’t find much information via Google, because it’s a topic widely discussed only in Chinese communities—communities you can find only by using Baidu and searches in Chinese. From what I’ve gathered online, Baidu was the first search engine to be abused this way many years ago by the Chinese, and they managed to curb it. Google, however, remains vulnerable, even though their team is aware of the problem.


P.S.: I’ve reported dozens of Chinese domains and subdomains to Google, with evidence, screenshots of the spammy pages, modified sitemaps to trap crawlers, redirect chains, etc. It’s been eight months, and all the attacker domains are still intact—only the victims’ domains show a steady collapse in their Google rankings.
 
as someone who sucks at BH I have very little idea of what you're talking about, but I still marveled in the creativity of these black hatters. I would be shocked if this method doesn't get abused to death in the coming weeks now that everyone saw it :D
 
as someone who sucks at BH I have very little idea of what you're talking about, but I still marveled in the creativity of these black hatters. I would be shocked if this method doesn't get abused to death in the coming weeks now that everyone saw it :D
Curious to know BHW member opinions.
 
One bump, but would love to hear the community input & thoughts.
 
This method is wild and clearly against SEO norms. It's surprising that it's working, even though it seems like a clear abuse of the system. How long do you think it will last before Google catches on? Anyone else seen similar tactics or have advice on protecting against this?
 
Can you paste a sample in form of code, as this is very hard to get. At first impression it looks like something related to google redirect and in this case we are redirecting authority of multiple domains. Or what else we are doing.
I don't have a sample of code...

Please check the PDF file for more information:

VirusTotal:
Code:
https://www.virustotal.com/gui/url/09ca024331d16af30f368f04da11bebd23e18ca3519990ccf117ba419b487820?nocache=1

And you can download the file from the OP, or from:

Code:
https://limewire.com/d/unjSh#n17bejKwbK
 
Found this interesting piece of information on a website.

I’ve been following this method for several months now—one that normally shouldn’t work, yet works extremely well and drives insane amounts of traffic to the sites that use it. The method is black‑hat, it’s heavily combined with parasite SEO to boost the final results, and those who use it risk being harshly penalized by search engines. But they aren’t :)

The sites I constantly monitor that exploit this are still going strong, with fluctuations between 5K and 300K unique visitors per month depending on the scale of the “attack” at any given time, and they rank reasonably well. Behind all of them are always Chinese operators—because it originated there, and probably because in China it’s very cheap to buy such services, with the infrastructure already in place to get everything running as soon as you pay the subscription.

The results of this method are as follows:
  1. The crawler is trapped in an endless series of redirects that lead to pages built solely to receive traffic and “juice,” while in turn generating traffic and juice for other domains or subdomains.
  2. The attacker’s main domain climbs in ranking, reaching good positions on long‑tail keywords.
  3. Domains that fall victim to parasite‑SEO + spider‑pool tactics begin to suffer steep traffic drops, regardless of their authority (you can easily see this happening on some U.S. news publications). This happens for several reasons: they either have an open‑redirect bug that lets attackers create redirects, or an internal search function that’s indexable, or they allow the creation of pages where ******** links point to domains in the spider‑pool. Affected are CMSs, plugins, or simply forums or blogs that leave comments and posts open. Since I’ve been watching this phenomenon I haven’t seen a single compromised site used in combination—just open redirects, spammy pages, subdomains and domains set up to redirect, forums and blogs spammed with links that are often nofollow. Basically, anyone with the technical skills can do this without having to hack sites or servers.
  4. Abused domains A, B and C—unwittingly caught up in the scheme—suffer a drop in their crawl budget allocated by Google, but this only shows up on their legitimate pages. The parasitic pages—where the redirects originate and that belong to the spider pool—get crawled by Google multiple times a day (sometimes hundreds of times a day), whereas the real, normal pages no longer get visited because the entire crawl budget has been consumed by the parasitic pages.
  5. Webmasters of the abused domains take a long time to realize what’s happening, which leads to an unexplained collapse in their traffic. Although all spider‑pool actions appear in Google Search Console in one form or another, they look like random spam that shouldn’t have any effect. The effect only becomes visible when, over a few months, hundreds of thousands of pages that shouldn’t exist appear, and hundreds of thousands of hits on pages returning 404 errors—because those paying for such services often set up their spam campaigns poorly, or use another parasite‑SEO method to index keywords in the victim site’s internal search (a crappy approach that only creates problems for the victims and zero advantage for the spammers).
How it works:

The attacker places on Page A (a high‑authority newspaper’s site) a link that is forced to redirect to Site B (a large retailer’s site), which in turn redirects to Site C (a prestigious university’s site), which then finally forces the crawler onto the attacker’s own site. In the end, the attacker siphons off a little “juice” from each site involved in the redirect chain. This defies every unwritten rule of SEO and shouldn’t work this way—but it does, because there are millions of these actions happening day after day.

Example:
Spammy page with links →
domainA.com/redir.php?out=https://domainb.com/link?u=https://domainC.com/url?out=https://anotherattackerdomain.com/internalpage.html →
attackersubdomainA/pagewithlinks+sitemapRedirect →
attackersubdomainB/pagewithlinks+sitemapRedirect →
attackersubdomainC/pagewithlinks+sitemapRedirect →
attackermoneysite+sitemapRedirect → infinite redirects

Attackers always use on their domains and subdomains a combination of many external links and sitemaps that force search engines to treat the redirects as legitimate. Very often they also involve expired domains, which they configure to create and delete spammy subdomains on an endless loop.



I know it sounds convoluted—even when you see the entire flow live in front of you—and I’d like to provide clear examples with GSC screenshots, stats, etc., but I can’t share any of that right now without revealing private data. The results are hard to explain because everything that happens contradicts what we know about how Google works, what it penalizes, and what it rewards. In practice, the search engine is so confused by the millions of redirects and spammy link pages that its anti‑spam algorithms lose their intended effect. The fact that victim domains plummet in a few months makes this method useful both for SEO gains and for negative SEO.

The study below explains some of the attack methods and their outcomes, but the method has since been combined with parasite SEO and other rather rudimentary techniques, which together deliver exceptionally good results. You won’t find much information via Google, because it’s a topic widely discussed only in Chinese communities—communities you can find only by using Baidu and searches in Chinese. From what I’ve gathered online, Baidu was the first search engine to be abused this way many years ago by the Chinese, and they managed to curb it. Google, however, remains vulnerable, even though their team is aware of the problem.



P.S.: I’ve reported dozens of Chinese domains and subdomains to Google, with evidence, screenshots of the spammy pages, modified sitemaps to trap crawlers, redirect chains, etc. It’s been eight months, and all the attacker domains are still intact—only the victims’ domains show a steady collapse in their Google rankings.
man, was a lot to read, but good info, thx for educating me. Do you also have other pieces of info like this?
 
Back
Top