BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
A long-running SEO poisoning campaign codenamed BengalSEO, operating from Rajasthan, India since 2015, manipulates Bing search results to promote malicious lure pages The campaign uses sophisticated Black Hat SEO techniques including DOM shuffling, keyword stuffing, backlink spamming, and abuse of legitimate hosting platforms (GitHub Pages, ReadTheDocs, Google Sites) to appear at the top of search results Two IT service providers, WeConnect Solutions LLC and Garage2Global, drive the operation, l
Analysis
TL;DR
- A long-running SEO poisoning campaign codenamed BengalSEO, operating from Rajasthan, India since 2015, manipulates Bing search results to promote malicious lure pages
- The campaign uses sophisticated Black Hat SEO techniques including DOM shuffling, keyword stuffing, backlink spamming, and abuse of legitimate hosting platforms (GitHub Pages, ReadTheDocs, Google Sites) to appear at the top of search results
- Two IT service providers, WeConnect Solutions LLC and Garage2Global, drive the operation, leveraging their web development expertise to build malicious infrastructure and a traffic distribution system (TDS)
- The primary payload is MayaBot malware, which enables C2 communication, system monitoring, and XMRig cryptocurrency mining, delivered via JavaScript droppers disguised as legitimate software installers
- The campaign employs a multi-stage infection chain with CAPTCHA gating, browser fingerprinting via Matomo analytics, redirector chains, and dual delivery paths: malware download or tech support scam call centers
Why It Matters
This campaign demonstrates how cybercriminals with legitimate business fronts can weaponize professional SEO and web development skills to manipulate search engine rankings at scale, making detection increasingly difficult. The use of trusted hosting platforms and sophisticated evasion techniques like DOM shuffling highlights an evolving threat landscape where the line between legitimate digital marketing and malicious SEO poisoning continues to blur.
Technical Details
- SEO Poisoning Techniques: BengalSEO employs backlinks (the Vizio decoy page accumulated 2,000 backlinks from 167 unique domains), DOM injection, DOM shuffling (dynamic reordering of HTML elements via JavaScript to bypass spam filters), keyword stuffing, and aggressive user-generated content spam across forums and comment sections
- Traffic Distribution System (TDS): A multi-layered redirector chain gates victims through CAPTCHA challenges (Cloudflare Turnstile/hCaptcha) to filter bots, uses Matomo analytics on domain "stats.us3[.]org" for browser fingerprinting and victim profiling, and routes traffic to appropriate landing pages based on client characteristics
- Payload Delivery: The final landing pages present fake software downloads (antivirus, gaming, taxation utilities, streaming service activation). Clicking "Download for Windows" delivers a ZIP archive containing a JavaScript dropper that executes via wscript.exe to install MayaBot, while users are redirected to the legitimate software page after 40 seconds to reduce suspicion
- Infrastructure: Malicious lure pages impersonate technical support portals for brands like Bitdefender, Vizio, and streaming services. Payload delivery domains include ustechnio.com, tax.dll.lat, u320.my, reficon.pro, and pltechoo.pro. Legitimate hosting platforms (github.io, pages.dev, sites.google.com, readthedocs.io) are weaponized to leverage their domain reputation in search rankings
- MayaBot Capabilities: Custom malware active since 2022 providing command-and-control (C2) functionality, system monitoring, and XMRig cryptocurrency miner deployment, representing the campaign's primary automated infection vector
Industry Insight
- Search engine providers, particularly Microsoft Bing, should prioritize detecting and demoting pages that exhibit DOM shuffling patterns and abnormal backlink velocity from low-quality UGC sources, as these are emerging indicators of SEO poisoning campaigns
- Organizations should educate users about the tactic of hijacking brand-related search queries (e.g., "Bitdefender Central login") and the danger of downloading software from pages hosted on seemingly legitimate platforms like GitHub Pages or ReadTheDocs
- The convergence of legitimate IT service providers with cybercriminal operations suggests that threat intelligence sharing between cybersecurity firms and SEO/digital marketing companies could yield earlier detection of campaigns that weaponize professional web development capabilities
Disclaimer: The above content is generated by AI and is for reference only.