AI Security AI安全 6h ago Updated 1h ago 更新于 1小时前 41

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams BengalSEO毒化Bing搜索结果投放MayaBot和技术支持诈骗

A long-running SEO poisoning campaign codenamed BengalSEO, operating from Rajasthan, India since 2015, manipulates Bing search results to promote malicious lure pages The campaign uses sophisticated Black Hat SEO techniques including DOM shuffling, keyword stuffing, backlink spamming, and abuse of legitimate hosting platforms (GitHub Pages, ReadTheDocs, Google Sites) to appear at the top of search results Two IT service providers, WeConnect Solutions LLC and Garage2Global, drive the operation, l BengalSEO是2015年起在印度运营的SEO poisoning攻击活动,由WeConnect Solutions LLC和Garage2Global两家IT服务商驱动,2026年3月由DFIR Report披露 攻击者利用黑帽SEO技术(反向链接、DOM注入、DOM洗牌、关键词堆砌)将恶意诱饵页面推至Bing搜索结果顶部,伪装成技术支持、软件下载和服务激活页面 MayaBot恶意软件自2022年起被用于C2通信、系统监控及XMRig加密货币挖矿,通过JavaScript Dropper经wscript.exe执行感染 攻击链包含TDS流量分发系统、Cloudflare Turnstil

62
Hot 热度
58
Quality 质量
52
Impact 影响力

Analysis 深度分析

TL;DR

  • A long-running SEO poisoning campaign codenamed BengalSEO, operating from Rajasthan, India since 2015, manipulates Bing search results to promote malicious lure pages
  • The campaign uses sophisticated Black Hat SEO techniques including DOM shuffling, keyword stuffing, backlink spamming, and abuse of legitimate hosting platforms (GitHub Pages, ReadTheDocs, Google Sites) to appear at the top of search results
  • Two IT service providers, WeConnect Solutions LLC and Garage2Global, drive the operation, leveraging their web development expertise to build malicious infrastructure and a traffic distribution system (TDS)
  • The primary payload is MayaBot malware, which enables C2 communication, system monitoring, and XMRig cryptocurrency mining, delivered via JavaScript droppers disguised as legitimate software installers
  • The campaign employs a multi-stage infection chain with CAPTCHA gating, browser fingerprinting via Matomo analytics, redirector chains, and dual delivery paths: malware download or tech support scam call centers

Why It Matters

This campaign demonstrates how cybercriminals with legitimate business fronts can weaponize professional SEO and web development skills to manipulate search engine rankings at scale, making detection increasingly difficult. The use of trusted hosting platforms and sophisticated evasion techniques like DOM shuffling highlights an evolving threat landscape where the line between legitimate digital marketing and malicious SEO poisoning continues to blur.

Technical Details

  • SEO Poisoning Techniques: BengalSEO employs backlinks (the Vizio decoy page accumulated 2,000 backlinks from 167 unique domains), DOM injection, DOM shuffling (dynamic reordering of HTML elements via JavaScript to bypass spam filters), keyword stuffing, and aggressive user-generated content spam across forums and comment sections
  • Traffic Distribution System (TDS): A multi-layered redirector chain gates victims through CAPTCHA challenges (Cloudflare Turnstile/hCaptcha) to filter bots, uses Matomo analytics on domain "stats.us3[.]org" for browser fingerprinting and victim profiling, and routes traffic to appropriate landing pages based on client characteristics
  • Payload Delivery: The final landing pages present fake software downloads (antivirus, gaming, taxation utilities, streaming service activation). Clicking "Download for Windows" delivers a ZIP archive containing a JavaScript dropper that executes via wscript.exe to install MayaBot, while users are redirected to the legitimate software page after 40 seconds to reduce suspicion
  • Infrastructure: Malicious lure pages impersonate technical support portals for brands like Bitdefender, Vizio, and streaming services. Payload delivery domains include ustechnio.com, tax.dll.lat, u320.my, reficon.pro, and pltechoo.pro. Legitimate hosting platforms (github.io, pages.dev, sites.google.com, readthedocs.io) are weaponized to leverage their domain reputation in search rankings
  • MayaBot Capabilities: Custom malware active since 2022 providing command-and-control (C2) functionality, system monitoring, and XMRig cryptocurrency miner deployment, representing the campaign's primary automated infection vector

Industry Insight

  • Search engine providers, particularly Microsoft Bing, should prioritize detecting and demoting pages that exhibit DOM shuffling patterns and abnormal backlink velocity from low-quality UGC sources, as these are emerging indicators of SEO poisoning campaigns
  • Organizations should educate users about the tactic of hijacking brand-related search queries (e.g., "Bitdefender Central login") and the danger of downloading software from pages hosted on seemingly legitimate platforms like GitHub Pages or ReadTheDocs
  • The convergence of legitimate IT service providers with cybercriminal operations suggests that threat intelligence sharing between cybersecurity firms and SEO/digital marketing companies could yield earlier detection of campaigns that weaponize professional web development capabilities

TL;DR

  • BengalSEO是2015年起在印度运营的SEO poisoning攻击活动,由WeConnect Solutions LLC和Garage2Global两家IT服务商驱动,2026年3月由DFIR Report披露
  • 攻击者利用黑帽SEO技术(反向链接、DOM注入、DOM洗牌、关键词堆砌)将恶意诱饵页面推至Bing搜索结果顶部,伪装成技术支持、软件下载和服务激活页面
  • MayaBot恶意软件自2022年起被用于C2通信、系统监控及XMRig加密货币挖矿,通过JavaScript Dropper经wscript.exe执行感染
  • 攻击链包含TDS流量分发系统、Cloudflare Turnstile/hCaptcha人机验证、Matomo浏览器指纹追踪,以及利用github.io、pages.dev等合法托管平台提升搜索排名

为什么值得看

本文揭示了SEO poisoning攻击从单纯流量劫持向恶意软件分发和电话诈骗复合化演进的完整攻击链,展示了黑帽SEO技术与合法基础设施滥用相结合的现代网络犯罪模式,对搜索引擎安全防御和威胁情报分析具有重要参考价值。

技术解析

  • 黑帽SEO技术栈:攻击者使用反向链接(如Vizio诱饵页面拥有2000个反向链接和167个外部域名)、DOM注入、DOM洗牌(通过JavaScript动态重排HTML元素使爬虫看到不同内容以绕过垃圾过滤)和关键词堆砌,并大规模投放UGC垃圾评论生成反向链接
  • 流量分发系统(TDS)架构:采用重定向链作为门控机制,通过Cloudflare Turnstile或hCaptcha过滤自动化扫描器和爬虫,使用Matomo(stats.us3.org)或Google Tag Manager进行客户端浏览器指纹追踪和流量分析
  • 恶意软件投递链:最终落地页提供"Download for Windows"按钮,下载ZIP压缩包内含伪装为可执行文件的JavaScript Dropper,通过wscript.exe执行启动MayaBot感染;部分页面不投递载荷,而是引导用户拨打技术支持诈骗电话
  • 合法平台滥用策略:利用github.io、pages.dev、sites.google.com、readthedocs.io等具有高信任度和搜索排名的托管平台部署诱饵页面,weaponize平台声誉提升SEO效果

行业启示

  • 搜索引擎厂商需重新评估托管平台域名权重算法,加强对github.io、pages.dev等高信任域名的内容审核和异常SEO行为检测,防止合法基础设施被规模化滥用
  • 威胁情报社区应建立针对SEO poisoning攻击的自动化检测框架,重点关注反向链接异常增长、DOM动态篡改和跨平台诱饵页面集群等指标
  • 企业安全团队需将SEO poisoning纳入威胁建模,加强对员工和用户的 phishing awareness 培训,特别是针对技术支持诈骗和虚假软件下载的识别能力

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究