Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > BengalSEO Campaign Uses Search Poisoning to Spread Malware and Tech Support Scams

BengalSEO Campaign Uses Search Poisoning to Spread Malware and Tech Support Scams

By: Jordan Vector Cybersecurity Expert

Last updated: September 8, 2026

Human Written
BengalSEO Campaign Uses Search Poisoning to Spread Malware and Tech Support Scams
  • Campaigns related to search engine poisoning employ black hat SEO techniques to rank harmful counterfeit websites at the top of search results.

  • The BengalSEO operation uses traffic distribution systems and browser fingerprinting to drop MayaBot malware or route users to scam call centers.

  • Threat groups weaponize legitimate hosting platforms and compromised server infrastructure to evade security filters.

Recently, cybersecurity researchers made a huge discovery related to the poisoning of search engine optimization. The poisoning scheme is currently active and targets to infect computers with malicious malware via illegal tech-related phone calls.

Investigators at the DFIR Report discovered the threat network and named it BengalSEO. The long-running campaign originates from Rajasthan, India, and uses deceptive websites to infect systems.

Unmasking the IT Service Providers Behind BengalSEO

Security teams linked the operation to two Indian technology service providers. The entities behind the malicious infrastructure are Garage2Global and WeConnect Solutions LLC, formerly known as iConnect Soft Solutions LLC.

Garage2Global publicly presents itself as a digital marketing agency, website design company, and search engine optimization services provider. However, threat intelligence researchers found clear evidence showing that the company builds attack infrastructure. In fact, the operators use extensive web development skills to create and rank rogue lure pages.

The threat actor relies heavily on aggressive black hat SEO tactics, with the aim to rank on Microsoft Bing search results. Their deceptive web pages impersonate technical support portals, streaming setup sites, and software download pages. When unsuspecting users search for help topics, these malicious sites appear near the top of their search results.

Consequently, victims land on decoy portals for tax utilities, antivirus software, gaming applications, or smart television activation guides. One specific campaign hijacked search terms for security software logins to serve fraudulent links hosted on legitimate documentation platforms. The decoy pages feature prominent call-to-action buttons that launch the infection chain.

The threat group operates with clear financial motivation. They possess deep expertise in web development and search manipulation. Their infrastructure allows them to run multiple scam campaigns simultaneously while keeping their server locations hidden from security analysts.

Black Hat SEO Tactics and Traffic Redirection Chains

This threat group operates aggressively by using different methods to improve the search engine ranking algorithms. They overcrowd online forums, community boards, and the comments sections of various postings with user-generated spam to create hundreds of thousands of backlinks all at once.

An example is a single decoy page hosted on GitHub that contained thousands of backlinks coming from hundreds of unique external domains. In addition, the operators use DOM shuffling to reorder page elements dynamically using embedded JavaScript code. This technique tricks web crawlers into seeing duplicate guides deployed across hundreds of web domains as completely unique pages.

To manage victims, BengalSEO uses a complex traffic distribution system to route web traffic. The system relies on such screening methods as Cloudflare Turnstile or hCaptcha to block security scanners, automated crawlers, and unwanted bots.

Furthermore, the threat actors deploy legitimate privacy analytics tools, such as Matomo to track and fingerprint user web browsers on the client side. The redirector chain will first gather the victim data. Then, it will send the browser to a payload delivery site or a fraudulent tech support call center landing page.

Instead of relying solely on one analytics engine, the operators also deploy tracking utilities like Google Tag Manager across distinct hosting services. The traffic distribution system evaluates each incoming connection carefully before deciding whether to serve malware or display a phone number.

Delivering MayaBot Malware and Fake Support Scams

The final stage of the infection chain delivers destructive payloads or directs users to scam call centers. In payload campaigns, users click download links for fake software updates and receive a malicious ZIP archive.

Inside the downloaded folder, a JavaScript dropper executes through the legitimate Windows Script Host process. Therefore, the dropper runs MayaBot, a custom threat used by the group since 2022 to monitor systems, maintain command-and-control communication, and deploy cryptocurrency miners like XMRig.

Alternatively, the landing page displays fake security alerts instructing users to call a phone number. These call centers trick callers into paying for fake technical assistance – or providing sensitive remote access to their computers.

The operators instruct users to resolve fake security flags associated with legitimate service accounts. Consequently, victims lose money while giving scammers direct access to their personal devices.

Overall, the operators continue registering new web domains across registry platforms like Namecheap and Spaceship while hosting decoy pages on GitHub. Furthermore, the group heavily favors proxy services to shield origin servers hosted on web platforms like Hostmaza.

Consequently, the group rotates web domains and updates code repositories frequently to avoid security blocks and domain takedowns.

The disclosure arrives alongside reports of parallel SEO manipulation tactics around the world. Cybersecurity teams at Check Point identified a sustained cyber campaign targeting government and educational websites in South America.

The Chinese-speaking cluster known as Gambling Goblin compromises legitimate web servers to host stealthy phishing redirects. This cluster shares close ties with established threat actors that target online gambling platforms across Asia.

The attackers install custom Apache server modules to reverse-proxy visitors toward illegal gambling portals and fake mobile app stores. Moreover, they disable content security policy headers so that the injected scripts could function undetected on the hacked websites.

Having gained entrance to the systems of the victims, the hackers utilize Linux-based toolkits, password thieves, SSH brute-force programs, and backdoor installations to control compromised systems.

In addition, hijacking authentic state-owned domains enables the gang to take advantage of the web reputation of such domains and push malicious pages up global search results.

The threat actors pose as trusted platforms like Google Play, the Microsoft Store, and Amazon to manipulate rankings. This global trend demonstrates that cybercriminals increasingly rely on search index poisoning to reach broad audiences.

Australian police arrested a 55-year-old man accused of running a dark web drug operation using encrypted platforms and cryptocurrency. Police seized 168 grams of crystal meth and 51 grams of cocaine.

Share this article

You might also like

Hacker Claims 46 Million Claro Brazil Phone Numbers Linked to CPF IDs

Hacker Claims 46 Million Claro Brazil Phone Numbers Linked to Tax IDs

A hacker known as GordonFreeman claims he broke into Claro Brazil’s system through an exposed API. The alleged leak reportedly…

September 7, 2026
Berlin District Blocks CrowdStrike Probe After Rhysida Ransomware Attack

Berlin District Refuses CrowdStrike Security Scan After Rhysida Ransomware Attack

Berlin’s Senate Chancellery hired CrowdStrike to search for signs of a recent ransomware hack. The Lichtenberg district refuses to let…

September 7, 2026
Shipup Cyberattack Exposes Customer Data From Micromania and Easypara

Shipup Cyberattack Exposes Retail Customer Data in Supply Chain Security Breach

Cyberattack on delivery tracking service Shipup has revealed the names, emails, and phone numbers of the customers of Micromania and…

September 4, 2026

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.