BengalSEO Campaign Poisons Bing Results to Spread MayaBot Malware and Scam Call Centres
Researchers at the DFIR Report have uncovered a large-scale search engine poisoning operation called BengalSEO, active since at least 2015 and run out of Rajasthan, India. Two IT service providers, WeConnect Solutions LLC (formerly iConnect Soft Solutions LLC) and Garage2Global, are said to be behind the scheme. While Garage2Global presents itself as a legitimate web design and SEO company, researchers found evidence it builds malicious web infrastructure used to poison search results and lure victims.
The campaign uses black hat SEO tactics to create fake lure pages that rank in search results such as Bing. These pages feed into a traffic distribution system that filters and redirects visitors, either to a custom malware called MayaBot or to fraudulent tech support scam call centres. MayaBot has been in use since 2022 and gives attackers remote control over infected systems, monitoring capability, and the ability to install the XMRig cryptocurrency miner to hijack victims' computing power.
The operation is notably sophisticated, using a legitimate analytics tool called Matomo to track and fingerprint victims, and employing cloaking techniques to hide malicious content from security researchers while still reaching real users through search engines.
Key Takeaway: Train staff to be cautious of unexpected search results promising software fixes or tech support, and use reputable security software that can detect malicious redirects before they reach a download or scam call.