CYBERSECURITY researchers have disclosed a large-scale SEO poisoning operation aimed at hijacking Bing search results to push malware payloads and tech-support scams. The operation, named BengalSEO and traced to Rajasthan, India, has been active since at least 2015 and is run by two IT firms: WeConnect Solutions LLC (formerly iConnect Soft Solutions LLC) and Garage2Global.
The campaign builds lure pages that use Black Hat SEO techniques, backlink spam and DOM manipulation to climb search rankings, linking users to a redirect chain that ends at attacker-controlled domains hosting MayaBot malware or pages claiming to offer tech-support assistance.
MayaBot functions as a C2 beacon and system monitor, while also delivering an XMRig miner. The campaign deploys a traffic distribution system to route, track and cloak traffic and to funnel victims through a chain of redirectors, with Matomo fingerprinting used on the client side for victim profiling.
The lure pages impersonate legitimate services and often prompt users to download ZIP archives via deceptive pages such as “Get Started” buttons; the ZIP contains a JavaScript dropper that launches MayaBot through wscript[.]exe. The operation also intercepts traffic using a TDS and leverages hosting on platforms like github[.]io and readthedocs[.]io to maintain legitimacy and evade detection.
Dozens of BengalSEO-linked GitHub accounts were identified, with activity concentrated 2025–early 2026; domain registration spans .my, .shop and .info, and hosting is heavily Cloudflare-proxied. In some cases the final landing pages route users to a BengalSEO scam number or direct them to cybercrime‑tainted service portals.