thedfirreport.com
BengalSEO Campaign Delivers Malware via SEO Poisoning
Article Content
In March 2026, a significant SEO poisoning campaign named BengalSEO was identified, attributed to two IT service providers in Rajasthan, India. This operation has been active since at least 2015, utilizing Black Hat SEO techniques to create lure pages that redirect users to tech support scams and malware deployment. The malware, named MayaBot, enables command-and-control functions and has been used since 2022. The campaign affects users searching for legitimate tech support and software downloads, leading them to malicious sites. Evidence suggests that the operation is financially motivated and employs sophisticated traffic distribution systems to optimize its reach. The DFIR Report has linked the operation to WeConnect Solutions LLC and Garage2Global, both of which have been implicated in developing malicious web infrastructure. The campaign's impact is widespread, targeting unsuspecting victims through manipulated search results on Microsoft Bing.
Key Points: • BengalSEO has been active since 2015, using SEO poisoning to deliver malware. • The custom malware, MayaBot, facilitates command-and-control and system monitoring. • The operation is linked to two IT service providers in Rajasthan, India.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.