BengalSEO Campaign Delivers Malware via SEO Poisoning

BengalSEO Campaign Delivers Malware via SEO Poisoning

First seen 8 Sep 2026, 10:02 UTC Thehackernewsthedfirreport.comdeveloper.mozilla.org 69.5

Article Content

Browse articles
ThreatCluster

In March 2026, a significant SEO poisoning campaign named BengalSEO was identified, attributed to two IT service providers in Rajasthan, India. This operation has been active since at least 2015, utilizing Black Hat SEO techniques to create lure pages that redirect users to tech support scams and malware deployment. The malware, named MayaBot, enables command-and-control functions and has been used since 2022. The campaign affects users searching for legitimate tech support and software downloads, leading them to malicious sites. Evidence suggests that the operation is financially motivated and employs sophisticated traffic distribution systems to optimize its reach. The DFIR Report has linked the operation to WeConnect Solutions LLC and Garage2Global, both of which have been implicated in developing malicious web infrastructure. The campaign's impact is widespread, targeting unsuspecting victims through manipulated search results on Microsoft Bing.

Key Points: • BengalSEO has been active since 2015, using SEO poisoning to deliver malware. • The custom malware, MayaBot, facilitates command-and-control and system monitoring. • The operation is linked to two IT service providers in Rajasthan, India.

Ask AI about this cluster

Timeline

2026-03-01
BengalSEO campaign discovered
The DFIR Report identified a widespread SEO poisoning campaign leading to malware and tech support scams.
The Hacker News
2026-08-24
DFIR Report publishes technical analysis
A detailed analysis of the BengalSEO operation was published, revealing its methods and the malware used.
thedfirreport.com
2026-09-08
Articles published on BengalSEO
Both The Hacker News and DFIR Report published articles detailing the ongoing BengalSEO campaign and its implications.
The Hacker News