Does this match what you’re seeing?
- Visitors from Google end up on a spam or scam site
- Mobile visitors are redirected but desktop visitors aren’t
- The redirect only happens on the first visit
Malicious redirects are designed to hide from site owners: they often trigger only for visitors arriving from search engines, on mobile, or on a first visit.
Reproduce it
- Use a private window on mobile data
- Click through from a Google search result for your site
- Use an online redirect checker that shows each hop
Where redirect code hides
1. .htaccess
Look in public_html/.htaccess and every subfolder’s .htaccess for rules checking HTTP_REFERER (google, bing) or HTTP_USER_AGENT (android, iphone) and redirecting to unfamiliar domains:
RewriteCond %{HTTP_REFERER} (google|bing|yahoo) [NC]
RewriteRule .* https://unfamiliar-domain.example/ [R=302,L]
2. PHP files
Injected code at the top of index.php, wp-config.php or theme functions.php — often long unreadable strings using base64_decode, eval or gzinflate. How to find malicious files on your website
3. The database
In WordPress, check wp_options for siteurl and home values, and search posts and options for <script tags and unfamiliar domains.
4. JavaScript
Injected <script> tags in theme files or appended to legitimate .js files.
Remove it properly
Deleting the redirect alone isn’t enough; the code that injected it usually remains. Follow My website has been hacked: what to do from the start.