-
Campaigns related to search engine poisoning employ black hat SEO techniques to rank harmful counterfeit websites at the top of search results.
-
The BengalSEO operation uses traffic distribution systems and browser fingerprinting to drop MayaBot malware or route users to scam call centers.
-
Threat groups weaponize legitimate hosting platforms and compromised server infrastructure to evade security filters.
Recently, cybersecurity researchers made a huge discovery related to the poisoning of search engine optimization. The poisoning scheme is currently active and targets to infect computers with malicious malware via illegal tech-related phone calls.
Investigators at the DFIR Report discovered the threat network and named it BengalSEO. The long-running campaign originates from Rajasthan, India, and uses deceptive websites to infect systems.
Unmasking the IT Service Providers Behind BengalSEO
Security teams linked the operation to two Indian technology service providers. The entities behind the malicious infrastructure are Garage2Global and WeConnect Solutions LLC, formerly known as iConnect Soft Solutions LLC.
Garage2Global publicly presents itself as a digital marketing agency, website design company, and search engine optimization services provider. However, threat intelligence researchers found clear evidence showing that the company builds attack infrastructure. In fact, the operators use extensive web development skills to create and rank rogue lure pages.
The threat actor relies heavily on aggressive black hat SEO tactics, with the aim to rank on Microsoft Bing search results. Their deceptive web pages impersonate technical support portals, streaming setup sites, and software download pages. When unsuspecting users search for help topics, these malicious sites appear near the top of their search results.
Consequently, victims land on decoy portals for tax utilities, antivirus software, gaming applications, or smart television activation guides. One specific campaign hijacked search terms for security software logins to serve fraudulent links hosted on legitimate documentation platforms. The decoy pages feature prominent call-to-action buttons that launch the infection chain.
The threat group operates with clear financial motivation. They possess deep expertise in web development and search manipulation. Their infrastructure allows them to run multiple scam campaigns simultaneously while keeping their server locations hidden from security analysts.
Black Hat SEO Tactics and Traffic Redirection Chains
This threat group operates aggressively by using different methods to improve the search engine ranking algorithms. They overcrowd online forums, community boards, and the comments sections of various postings with user-generated spam to create hundreds of thousands of backlinks all at once.
An example is a single decoy page hosted on GitHub that contained thousands of backlinks coming from hundreds of unique external domains. In addition, the operators use DOM shuffling to reorder page elements dynamically using embedded JavaScript code. This technique tricks web crawlers into seeing duplicate guides deployed across hundreds of web domains as completely unique pages.
To manage victims, BengalSEO uses a complex traffic distribution system to route web traffic. The system relies on such screening methods as Cloudflare Turnstile or hCaptcha to block security scanners, automated crawlers, and unwanted bots.
Furthermore, the threat actors deploy legitimate privacy analytics tools, such as Matomo to track and fingerprint user web browsers on the client side. The redirector chain will first gather the victim data. Then, it will send the browser to a payload delivery site or a fraudulent tech support call center landing page.
Instead of relying solely on one analytics engine, the operators also deploy tracking utilities like Google Tag Manager across distinct hosting services. The traffic distribution system evaluates each incoming connection carefully before deciding whether to serve malware or display a phone number.
Delivering MayaBot Malware and Fake Support Scams
The final stage of the infection chain delivers destructive payloads or directs users to scam call centers. In payload campaigns, users click download links for fake software updates and receive a malicious ZIP archive.
Inside the downloaded folder, a JavaScript dropper executes through the legitimate Windows Script Host process. Therefore, the dropper runs MayaBot, a custom threat used by the group since 2022 to monitor systems, maintain command-and-control communication, and deploy cryptocurrency miners like XMRig.
Alternatively, the landing page displays fake security alerts instructing users to call a phone number. These call centers trick callers into paying for fake technical assistance – or providing sensitive remote access to their computers.
The operators instruct users to resolve fake security flags associated with legitimate service accounts. Consequently, victims lose money while giving scammers direct access to their personal devices.
Overall, the operators continue registering new web domains across registry platforms like Namecheap and Spaceship while hosting decoy pages on GitHub. Furthermore, the group heavily favors proxy services to shield origin servers hosted on web platforms like Hostmaza.
Consequently, the group rotates web domains and updates code repositories frequently to avoid security blocks and domain takedowns.
Global SEO Manipulation Trends and Server Hijacking
The disclosure arrives alongside reports of parallel SEO manipulation tactics around the world. Cybersecurity teams at Check Point identified a sustained cyber campaign targeting government and educational websites in South America.
The Chinese-speaking cluster known as Gambling Goblin compromises legitimate web servers to host stealthy phishing redirects. This cluster shares close ties with established threat actors that target online gambling platforms across Asia.
The attackers install custom Apache server modules to reverse-proxy visitors toward illegal gambling portals and fake mobile app stores. Moreover, they disable content security policy headers so that the injected scripts could function undetected on the hacked websites.
Having gained entrance to the systems of the victims, the hackers utilize Linux-based toolkits, password thieves, SSH brute-force programs, and backdoor installations to control compromised systems.
In addition, hijacking authentic state-owned domains enables the gang to take advantage of the web reputation of such domains and push malicious pages up global search results.
The threat actors pose as trusted platforms like Google Play, the Microsoft Store, and Amazon to manipulate rankings. This global trend demonstrates that cybercriminals increasingly rely on search index poisoning to reach broad audiences.
Australian police arrested a 55-year-old man accused of running a dark web drug operation using encrypted platforms and cryptocurrency. Police seized 168 grams of crystal meth and 51 grams of cocaine.