Cybersecurity researchers have unmasked 'BengalSEO,' a massive SEO poisoning campaign operating out of Rajasthan that uses Bing search results to deploy MayaBot malware and tech support scams.
- The BengalSEO campaign has been active since at least 2015.
- Operations are traced back to Rajasthan, India.
- The primary goal is deploying MayaBot malware and executing tech support scams.
- Two IT service providers, WeConnect, are identified as key drivers.
In a major cybersecurity breakthrough, researchers have exposed a sprawling and sophisticated SEO poisoning campaign codenamed BengalSEO. This campaign strategically manipulates search engine results to lure unsuspecting users into a trap of malware deployment and fraudulent tech support services.
According to findings by the DFIR Report, this operation has been active since 2015, operating primarily out of the Indian state of Rajasthan. The investigation points toward two IT service providers, identified as WeConnect, as the driving force behind this long-standing digital deception.
The Mechanics of SEO Poisoning
The attackers utilize 'SEO poisoning' to hijack the visibility of search results on Bing. By optimizing malicious websites for specific high-intent keywords, they ensure that their fraudulent links appear at the top of search queries. Once a user clicks these links, they are often redirected to sites that trigger the download of MayaBot, a potent malware designed for system compromise.
Why This Matters
BozokMedia analysis shows that the longevity of this campaign—spanning nearly a decade—highlights a significant failure in detecting long-term, localized cybercrime hubs. It underscores how legitimate-looking IT services can be weaponized to facilitate cross-domain privilege escalation and massive identity exposure.
The weaponization of search engine trust represents one of the most difficult attack vectors to defend against in the modern era.
The campaign is not just about simple malware; it is a complex ecosystem where identity exposure unlocks active attack paths. By mapping these routes, security professionals can better identify choke points to sever breach paths before they escalate into full-scale data thefts.
Historical Background
While SEO manipulation is not new, the scale of BengalSEO is unprecedented. Most cyber campaigns are ephemeral, but the ability of this group to maintain operations from a single region for over eight years demonstrates a high level of organizational stability and evasion capability.
Frequently Asked Questions
1. How can I tell if a search result is part of an SEO poisoning attack?
Always check the URL carefully. If the website looks suspicious or asks for immediate software downloads, avoid it and use official sources.
2. What should I do if I suspect I have downloaded MayaBot?
Immediately disconnect your device from the internet and run a deep scan using reputable, updated antivirus software.