BengalSEO Manipulates Bing Search Results to Promote MayaBot and Tech Support Frauds

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Revelations about an Extensive Cybersecurity Threat: The BengalSEO Campaign

Cybersecurity analysts have brought to light a significant search engine optimization (SEO) poisoning operation, facilitating the deployment of malware and perpetration of tech support fraud.

Uncovered by the DFIR Report in March 2026, this initiative, dubbed BengalSEO, has been active since at least 2015 within the Indian state of Rajasthan.

The operation is reportedly orchestrated by two IT service firms: WeConnect Solutions LLC (formerly known as iConnect Soft Solutions LLC) and Garage2Global.

Though Garage2Global positions itself as a provider of website design, SEO, and digital marketing services, the cyber threat intelligence platform revealed that the entity is involved in crafting malicious web frameworks utilized in SEO poisoning tactics linked to the BengalSEO operation.

According to the DFIR Report, “This group employs extensive SEO and web development expertise to fabricate and disseminate lure pages using various Black Hat SEO strategies.”

These lure pages are intricately interwoven with a sophisticated traffic distribution system, engineered to direct, monitor, and filter traffic toward malicious payloads and tech support frauds.

Among the payloads identified is a custom malware known as MayaBot, which facilitates command-and-control (C2) operations, system surveillance, and the delivery of an XMRig cryptocurrency miner. BengalSEO has reportedly employed MayaBot since 2022 as part of its operational framework.

Described as a financially driven threat actor, the group possesses an impressive grasp of black hat SEO methodologies and web development, enabling the creation and promotion of a myriad of deceitful lure pages intended to disseminate MayaBot malware or coax victims into contacting their scam call centers.

Additionally, it utilizes a sophisticated traffic distribution system (TDS) to manage traffic flow, analyze campaign efficacy, and obscure its activities.

Specifically, the TDS functions as a gatekeeper, channeling victims toward domains designated for payload delivery through a series of redirects, while employing a legitimate analytics service known as Matomo for victim identification and tracking.

The operation begins with a network of deceptive lure pages promoted using SEO poisoning tactics, thereby ensuring these pages rank prominently in Microsoft Bing search results.

These counterfeit pages impersonate legitimate technical support and service activation portals for streaming platforms, alongside offering downloads for antivirus applications, gaming software, and tax-related utilities, as well as facilitating the activation of credit, healthcare, and gift cards.

An illustrative instance hijacks search queries for “bitdefender central how to login,” directing users to a fraudulent link hosted on readthedocs[.]io.

This page features a conspicuous “Get Started” button that initiates an infection sequence, redirecting unwitting users through a series of intermediaries to profile their web browsers before arriving at the final landing page.

The DFIR Report elaborated, “BengalSEO utilized backlinks, DOM injection, DOM shuffling, and keyword stuffing to sustain its operations through Black Hat SEO techniques.”

Moreover, the report highlights their application of aggressive user-generated content (UGC) spam for large-scale backlink creation.

This practice entails inundating forums and comment sections with hyperlinks to lure pages (e.g., “viziocomsetupentercode.github[.]io”), enticing readers to effortlessly set up their smart TVs by adhering to “simple on-screen instructions.” For example, the Vizio lure page boasts 2,000 backlinks and 167 unique external domains linking to it.

This evidence suggests that BengalSEO heavily relies on an elevated volume of backlinks to manipulate search engine ranking algorithms, artificially heightening the visibility of lure pages within search engine results.

DOM Shuffling, conversely, pertains to the technique of dynamically rearranging HTML elements through embedded JavaScript code, aimed at randomizing the Document Object Model (DOM) structure.

This strategy allows identical setup guides employed across numerous domains to appear distinctive, thus eluding spam detection systems.

Prior to presenting the primary payload page, the TDS-driven redirector domains display either a Cloudflare Turnstile or hCaptcha validation challenge, filtering out automated scanners, bots, and other undesired visitors.

Furthermore, both the lure and landing pages incorporate a Matomo tracking script designed to profile the user’s browser and relay that information to the domain “stats.us3[.]org.”

A check of the domain “stats.us3[.]org” on urlscan.io reveals 1,112 results at present, a decline from 1,190 during earlier analyses.

While Matomo is employed, it is not the sole analytics system utilized by BengalSEO, as lure pages hosted on platforms such as github.io and pages.dev typically leverage analytics services like Google Tag Manager, as noted by the DFIR Report.

At the conclusion of the redirection chain lies a final landing page presenting a download link and instructions for the fraudulent software.

Upon clicking the “Download for Windows” button, a ZIP archive is downloaded, subsequently redirecting users to the legitimate software page after a span of 40 seconds. Some domains used for payload delivery include:

  • ustechnio[.]com
  • tax.dll[.]lat
  • u320[.]my
  • reficon[.]pro
  • ñ[.]link
  • pltechoo[.]pro

Encased within the ZIP file is a JavaScript dropper for MayaBot, masquerading as an executable for the previously downloaded program. Upon execution, the JavaScript activates via “wscript.exe,” thus commencing the MayaBot infection process.

Alternatively, certain final pages may refrain from delivering payloads, instead redirecting victims to a contact page instructing them to call a BengalSEO scam number regarding supposed suspicious activity linked to their Bitdefender Central account.

BengalSEO has exploited reputable web hosting platforms such as github.io, pages.dev, sites.google.com, and readthedocs.io to facilitate their SEO poisoning endeavors, likely leveraging the inherent trust and credibility associated with these services to influence search engine rankings.

The DFIR Report additionally uncovered a multitude of BengalSEO-affiliated GitHub accounts, utilized for the development and hosting of lure pages.

These decoy pages receive consistent updates through commits, rotating redirector domains or temporarily substituting them with legitimate URLs to mitigate detection and replace blocked or removed domains.

From January 2024 to March 2026, up to 84 active BengalSEO GitHub accounts have been identified. Further scrutiny of the commit logs associated with these accounts has revealed email addresses linking them to Garage2Global (“wc[.]ci”). Below is a sample of several GitHub accounts and their corresponding Garage2Global addresses:

The bulk of the BengalSEO infrastructure is reported to have been established around August 2025 and has exhibited increased activity transitioning into late 2025 and early 2026. The domains have predominantly been registered under .my, .shop, and .info top-level domains (TLDs).

The DFIR Report noted, “Between 2023 and 2026, BengalSEO primarily registered domains through Spaceship (47.6%) and Namecheap (28.6%).”

To manage hosting, the group has shown a marked preference for Cloudflare (81.1%) as a means to proxy traffic, with Hostmaza acting as the origin host for 10.0% of domains.

An account responsible for some redirector domains (“wapp[.]live”) was suspended by Hostmaza earlier this year.

This disclosure arrives concurrently with Check Point Research’s revelations concerning a persistent campaign targeting Brazilian governmental and educational entities since mid-2025, with the intent to transform their websites into vehicles for SEO manipulation.

This activity has been linked to a Chinese-speaking cybercrime syndicate known as Gambling Goblin, with connections to Earth Berberoka (also referred to as GamblingPuppet), a known threat actor focusing on gambling websites across Asia since at least 2020.

The group is reported to be “operating localized phishing networks in Portuguese, Vietnamese, Spanish, and English, while also maintaining infrastructure capable of generating new domains on a daily basis,” according to the cybersecurity firm.

“Together, these revelations imply that this is not merely a local initiative, but a model engineered for global execution.”

The campaign entails the installation of malicious Apache modules on compromised servers, stealthily forwarding visitors to phishing pages controlled by the attackers, all while masking the source traffic to appear as if it originates from the legitimate domain.

The site’s own Content-Security-Policy (CSP) headers are stripped to permit the operation of injected content without obstruction.

Upon breaching the target, the threat actors deploy a Linux toolkit comprising a custom Go-based downloader (named DownPro), various backdoors (AlphaAgent, ChUser, and oRAT) for executing commands and enabling remote control, a 3snake-based password acquisition tool, an SSH brute-force mechanism, and a plugin-based reconnaissance agent.

The perpetrators have also been found installing custom Apache modules allowing the routing of visitors to the phishing pages. The precise entry point remains unclear.

The phishing pages masquerade as credible app stores, such as Google Play, Microsoft Store, and Amazon, exploiting the high-trust domains to enhance search rankings and ultimately promote online gambling and sports betting.

Three Scrabble tiles spelling SEO are placed upright on a wooden shelf against a plain green background.

Check Point concluded, “The likely aim is to achieve SEO manipulation at a vast scale.” By commandeering high-reputation domains, particularly among Brazilian government sites, the operators leverage that trust to elevate their content within search rankings and hijack ensuing traffic.

However, the same infrastructure may pose a more perilous threat: the phishing pages impersonate app-download destinations such as Google Play, Microsoft Store, and Amazon, positioning the operators a mere step away from delivering malware directly to their victims.

Source link: Thehackernews.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Ranjana Banerjee

I’m Ranjana Banerjee, Creative Content Manager at RSWEBSOLS in Kolkata, India, with 10+ years of experience in blogging, SEO, digital marketing, and e-commerce. I create high-quality content and SEO strategies that boost traffic, improve rankings, and help businesses grow in competitive markets.
Share the Love
Related News Worth Reading