Slot Gacor Hack: Removing Gambling Spam From Your Site
By Glenn Lyvers · Updated · 7 min read
If Google shows your site with Indonesian titles like “Slot Gacor Hari Ini”, “Situs Slot Online” or “Togel”, your site has been hacked to host gambling spam — and the reason you cannot see it is that the malware shows the spam only to search engines. The fix is to find and remove the cloaking code and its backdoors, then clear the spam URLs out of Google’s index.
What the slot gacor hack is
“Slot gacor” is Indonesian gambling slang for a slot machine that supposedly pays out often, and it is the headline keyword of a very large, very industrial SEO spam operation. The people behind it do not want your visitors. They want your domain’s standing with Google, which they borrow to rank gambling pages that could never rank on their own. The same campaigns use “judi online” (online gambling), “togel” (a lottery game), “situs slot”, “maxwin” and brand names of betting sites.
It hits every kind of site, but the favourite targets are domains with authority: universities, government offices, academic journals, nonprofits and long-established small businesses. Security researchers have documented it at scale on .edu, .gov and .ac domains, and on Open Journal Systems installations where Google ended up indexing gambling text in place of journal metadata. If you are on WordPress, it looks like a cousin of the Japanese keyword hack and the pharma hack, and it is cleaned the same way.
How to tell you have it
- Search results in Indonesian. Search
site:yourdomain.com slotorsite:yourdomain.com gacor. Any hits are the answer. - Your homepage title changes only in Google. The result shows a gambling title and description, but your homepage looks normal in the browser. That is cloaking.
- Search Console shows pages you never made. Thousands of new indexed URLs, spam queries in the Performance report, strange sitemaps under Sitemaps, or an owner you do not recognize under Users and permissions — see unknown owner in Search Console.
- New folders or files. Directories with gambling names in the web root,
index.phpfiles in upload folders, or thousands of generated.htmlfiles. - Hidden links. A block of gambling links in your footer that is invisible to people but visible in the page source — my guide to spam links injected into WordPress covers this variant.
Before you touch anything, take copies of what you see. Screenshot the search results and save the server’s access log. Those tell you when it started and where it came in; my guide to preserving evidence before cleanup explains what to keep.
How it hides from you
The core of this hack is a few lines of PHP that check who is asking. If the visitor’s user agent contains Googlebot, bingbot or similar, or the request came from a search engine’s IP range, the code serves the spam. Anyone else, including you, gets the real site. Some versions also check the Referer header and redirect visitors arriving from Google to a betting site, while leaving direct visits alone. That is the pattern in my guide to the cloaking hack.
You can see it for yourself from a terminal:
curl -s -A "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" https://yourdomain.com/ | grep -i -E "slot|gacor|togel|judi"
If that returns gambling text and a normal browser does not, you have confirmed cloaking. Some variants check real Google IP addresses rather than the user agent, in which case curl shows nothing. Search Console’s URL Inspection → View crawled page shows what Googlebot actually received.
Where the code usually lives
Expect more than one location. The generator is only the visible part; there is almost always a way back in.
| Location | What to look for |
|---|---|
index.php, wp-config.php, theme header.php / functions.php | User-agent checks, file_get_contents or curl calls to remote URLs, long encoded strings |
.htaccess | Rewrite rules sending unknown paths to a PHP file — see hacked .htaccess |
New directories and wp-content/uploads/ | Doorway page generators and thousands of spam pages — see doorway pages |
| Sitemaps | Extra sitemap files listing spam URLs — see hacked sitemap spam |
| Database | Spam posts, injected links in wp_posts, rogue options — see database malware |
mu-plugins, fake plugins, web shells | The backdoor that re-creates everything after you clean |
One case worth checking if you run a larger organization: a subdomain whose DNS still points at a service you stopped using. Attackers can claim the abandoned service and publish spam under your name without ever touching your server. My guide on hacked DNS versus a hacked website explains how to tell.
Cleaning it up, in order
- Lock the doors. Change hosting, FTP/SFTP, database and all WordPress admin passwords, and remove users you do not recognize.
- Replace core, plugins and themes with clean copies from official sources rather than editing infected files.
wp core verify-checksumsandwp plugin verify-checksums --allshow what was modified. - Remove the spam content: generated folders, spam sitemaps, rewrite rules, injected database rows.
- Hunt the persistence. Search for recently modified PHP files, PHP in uploads,
mu-plugins, scheduled tasks and hidden admins. My backdoor removal guide has the searches I run. - Find the entry point — usually an outdated plugin, a nulled theme, or reused credentials — and fix it.
- Re-test as Googlebot with the curl command above and with URL Inspection.
This hack is notorious for coming back, because the backdoors are designed to rebuild the spam from a remote server within hours. If it returned after you cleaned it, that is expected behaviour, not bad luck — and it is the point where I would stop doing it by hand.
Rather hand it to me?
Every job is done by me personally, at a flat price per site, with written findings.
Not sure which? Ask me first — I’ll tell you honestly if you can handle it yourself.
Getting the spam out of Google
Cleaning the server does not clean Google’s index. Thousands of spam URLs can sit in search results for weeks unless you help them out.
- Make the spam URLs return
404or, better,410 Gone. A 410 tells Google the removal is deliberate. - Delete the spam sitemaps from Search Console and submit your real sitemap again.
- Use the Removals tool for the worst URLs, or a URL prefix, to hide them quickly while Google recrawls.
- If Search Console shows a Security Issues or manual action notice, request a review once you are clean — see Search Console security issues.
My guide on removing spam URLs from Google’s index goes through each step, and ranking recovery after a hack covers what to expect afterwards. Most sites recover their rankings once the spam is gone and stays gone, but it takes weeks rather than days.
Common questions
What does slot gacor mean on my website?
Slot gacor is Indonesian gambling slang for a slot machine that supposedly pays out often. If it appears in Google results for your site, attackers have hacked the site to publish gambling spam, usually shown only to search engines so the owner does not notice. It needs a full cleanup, not just deleting the visible pages.
Why can't I see the gambling spam when I visit my site?
Because the malware uses cloaking. It checks the visitor's user agent, IP address or referrer and only shows the spam to search engine crawlers. You see your normal site. Test with curl using a Googlebot user agent, or use URL Inspection in Search Console to see what Google received.
How do I remove slot gacor spam from Google search results?
First clean the site so the spam URLs return 404 or 410. Then delete any spam sitemaps in Search Console, submit your real sitemap, and use the Removals tool for the worst URLs. Google drops the rest as it recrawls, which usually takes a few weeks.
Why does the judi online spam keep coming back?
Because a backdoor survived the cleanup. These campaigns plant several ways back in, such as web shells, mu-plugins, database payloads and code that re-downloads the spam from a remote server. Until every one of those and the original entry point are removed, the spam will reappear.
Will my Google rankings recover after the gambling hack?
Usually, yes, once the spam is completely gone and stays gone. Expect several weeks while Google recrawls and drops the spam URLs. Recovery is slower if Google issued a manual action, and it stalls if the site gets reinfected.
Why do hackers target my small site for gambling spam?
Because your domain has something they cannot buy: an age and reputation Google trusts. Gambling sites struggle to rank on their own, so attackers borrow the authority of legitimate sites. Government, university and long-established business sites are favourite targets for exactly that reason.
More than malware
Most people meet me in an emergency. It isn’t all I do.
I’ve been building and repairing systems since 1995. Whatever brought you here, there’s a good chance I can help with the rest of it too — and you’ll be dealing with the same person either way.
Hacked, but not WordPress?
Joomla, Drupal, Magento, Shopify, PrestaShop, Laravel, Node, IIS and plain HTML — cleaned the same way, priced the same way.
Take a look →Custom builds & AI systems
Plugins, custom applications, website chatbots and automation — built to do exactly what you need, maintained by the person who wrote them.
Take a look →Servers, speed, SEO & accessibility
Migrations, faster load times, technical SEO and accessibility fixes. Measured improvements, with the numbers to show you.
Take a look →Better web hosting
Fast, secure hosting with SSL and backups included at no extra charge. Clear pricing, no long-term contracts, no surprises.
Take a look →Classes & free tools
Rather learn to handle it yourself? I teach this, and I give away the tools I built for my own cleanups.
Take a look →Something else broken?
Half my work is untangling what someone else started, gave up on, or broke. Describe it in plain words and I’ll tell you honestly.
Take a look →Tell me what’s wrong. I’ll tell you what it takes.
No queue, no call centre, no sales pitch — one person who answers, quotes honestly, and does the work.