BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams.
The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect Solutions LLC (previously iConnect Soft Solutions LLC) and Garage2Global.
Although Garage2Global claims to be a website design, SEO, and digital marketing services provider, the cyber threat intelligence platform said it unearthed evidence indicating the company develops malicious web infrastructure used in SEO poisoning campaigns as part of the BengalSEO scam cluster.
“This group utilizes its extensive SEO and web development capabilities to create and promote lure pages with multiple Black Hat SEO techniques,” the DFIR Report said in a technical analysis published late last month. “These lure pages then tie into a sophisticated traffic distribution system to direct, track, and filter traffic to payloads and tech support scams.”
One of the payloads is a custom malware dubbed MayaBot, which is responsible for enabling command-and-control (C2), system monitoring, and delivering an XMRig cryptocurrency miner. BengalSEO is said to have leveraged MayaBot since 2022 to carry out the group’s operations.
The financially motivated threat actor has been described as possessing extensive knowledge of black hat SEO techniques and web development to create and promote a cluster of rogue lure pages to deliver MayaBot malware or dupe victims into calling their scam call centers. It also integrates a sophisticated traffic distribution system (TDS) to handle traffic flow, campaign performance, and cloaking.
Specifically, the TDS acts as a gating mechanism to lead victims to payload delivery domains through a redirector chain, while employing a legitimate privacy-first analytics service called Matomo for victim tracking and fingerprinting.
The starting point of the operation is a network of malicious lure pages that are promoted via SEO poisoning techniques so that they appear at the top of search results on Microsoft Bing. The decoy pages impersonate legitimate technical support and service activation portals for streaming services. They also claim to offer downloads for antivirus tools, gaming software, and taxation utilities, as well as activate credit, healthcare, and gift cards.
One such example hijacks searches for “bitdefender central how to login” to serve a fraudulent link hosted on readthedocs[.]io. The page features a prominent “Get Started” button that initiates the infection chain and routes unsuspecting users through a series of redirector domains to fingerprint their web browser before taking them to the appropriate final landing page.
“BengalSEO used backlinks, DOM injection, DOM shuffling, and keyword stuffing to enable their operation through Black Hat SEO techniques,” the DFIR Report noted. “BengalSEO uses aggressive user-generated content (UGC) spam to generate backlinks at scale.”
This involves flooding forums and comment sections with hyperlinks to the lure pages (e.g., “viziocomsetupentercode.github[.]io”), urging readers to set up their smart TV “easily” by following “simple on-screen instructions.” The Vizio decoy page, for instance, has 2,000 backlinks and 167 unique external domains that link to the site.
This suggests that BengalSEO is heavily relying on a high volume of backlinks to manipulate search engine ranking algorithms and artificially boost the visibility of the lure pages on search engine results.
DOM Shuffling, on the other hand, refers to the practice of dynamically reordering HTML elements using embedded JavaScript code with the goal of randomizing the Document Object Model (DOM) structure. This, in turn, allows identical setup guides deployed across hundreds of domains to appear unique to web crawlers and bypass spam filters.
Before being served the main payload page, the TDS-based redirector domains display a Cloudflare Turnstile or hCaptcha challenge to screen automated scanners, crawlers, bots, and other unwanted visitors. The lure and landing pages come embedded with a Matomo tracking script to profile the browser on the client-side and send the information to the domain “stats.us3[.]org.” A search for the domain “stats.us3[.]org” on urlscan.io yields 1,112 results as of writing, down from 1,190 at the time of analysis.
“Matomo was not the only analytics system used by BengalSEO, lure pages on hosting platforms such as github.io and pages.dev instead typically use analytics services such as Google Tag Manager,” the DFIR Report said.
At the other end of the redirection chain is the final landing page that contains a download link and instructions for using the fake software. Once the user clicks the “Download for Windows” button, it downloads a ZIP archive before redirecting the user to the legitimate software page after 40 seconds. Some of the domains used for payload delivery are listed below –
- ustechnio[.]com
- tax.dll[.]lat
- u320[.]my
- reficon[.]pro
- ñ[.]link
- pltechoo[.]pro
Present within the ZIP file is a JavaScript dropper for MayaBot that masquerades as an executable for the program downloaded in the previous stage. After execution, the JavaScript executes via “wscript.exe” to kick-start the MayaBot infection.
Alternatively, the final pages serve no payloads in some instances, instead redirecting the victim to a contact page that instructs them to call a BengalSEO scam number to address an issue with purported suspicious activity linked to their Bitdefender Central account.
BengalSEO has been observed using legitimate web page hosting platforms such as github.io, pages.dev, sites.google.com, and readthedocs.io to aid in their SEO poisoning efforts, likely weaponizing the trust and reputation of these services that factor into the search engine rankings.
The DFIR Report said it also identified multiple BengalSEO-linked GitHub accounts that were used for developing and hosting lure pages. The decoy pages are constantly updated via commits to rotate redirector domains or temporarily replace them with legitimate URLs so as to avoid detection and replace domains that have been blocked or taken down.
As many as 84 active BengalSEO GitHub accounts have been detected between Jan 2024 and March 2026. Further examination of the commit history made by these accounts has uncovered email addresses linking them to Garage2Global domains (“wc[.]ci”). A sample of some of the GitHub accounts and their associated Garage2Global addresses is as follows –
- activate-uhc-com-ucard – [email protected]
- activate-uhc-helpbook – [email protected]
- capitalonecredit – [email protected]
- help-line-center – [email protected]
- snehajaing2g – snehajaing2g@gmail
The bulk of the BengalSEO infrastructure is said to have been registered around August 2025 and later, with heightened activity continuing through late 2025 and early 2026. The domains have been registered across .my, .shop, and .info top-level domains (TLDs).
“Between 2023 and 2026, BengalSEO primarily registered domains through Spaceship (47.6%) and Namecheap (28.6%),” the DFIR Report said. “For hosting, the group heavily favored Cloudflare (81.1%) to proxy traffic, with Hostmaza serving as the origin host for 10.0% of domains.” One account managing some of the redirector domains (“wapp[.]live”) was suspended by Hostmaza earlier this year.
The disclosure comes as Check Point Research shared details of a sustained campaign targeting Brazilian government and educational institutions since mid-2025 to turn their websites into a weapon for SEO manipulation. The activity has been attributed to a Chinese-speaking cybercrime cluster known as Gambling Goblin, which has ties to Earth Berberoka (aka GamblingPuppet), a threat actor known for singling out gambling websites across Asia since at least 2020.
The group is “operating localized phishing networks in Portuguese, Vietnamese, Spanish, and English, while also maintaining infrastructure that generates new domains daily,” the cybersecurity company told The Hacker News. “Together, these findings suggest this is not a regional experiment, but a model designed for global scale.”
The campaign involves installing malicious Apache modules on victim servers that covertly reverse-proxy visitors to attacker-controlled phishing pages, while the traffic still appears to originate from the legitimate domain. The site’s own Content-Security-Policy (CSP) headers are removed to allow the injected content to run without being blocked.
Upon finding a way in, the threat actors deploy a Linux toolkit comprising a custom Go-based downloader (DownPro), several backdoors (AlphaAgent, ChUser, and oRAT) to run operator-issued commands and facilitate remote control, a 3snake-based password stealer, an SSH brute-forcer, and a plugin-driven reconnaissance agent. The attackers have also been found to install custom Apache modules that proxy visitors to the phishing pages. The exact initial access route is unknown.
The phishing pages pose as trusted app stores such as Google Play, Microsoft Store, and Amazon, leveraging the high-reputation domains to inflate search rankings and ultimately push online gambling and sports betting.
“The likely goal is SEO manipulation at scale,” Check Point said. “By hijacking trusted, high-reputation domains, many of them Brazilian government sites, the operators borrow that reputation to push their own content up the search rankings and hijack the traffic that follows. But the same infrastructure could serve a more dangerous end: the phishing pages impersonate app-download destinations such as Google Play, the Microsoft Store, and Amazon, which leaves the operators one step from pushing malware straight to victims.”
The post “BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams” appeared first on The Hacker News
Source:The Hacker News – [email protected] (The Hacker News)



