BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect
- 1. BengalSEO, a sprawling SEO poisoning campaign originating from Rajasthan, India, has been active since at least 2015, driven by IT service providers WeConnect Solutions LLC and Garage2Global.
- 2. The campaign utilizes Black Hat SEO techniques, including backlinks, DOM injection, DOM shuffling, and keyword stuffing, to manipulate search engine rankings and promote malicious lure pages.
- 3. BengalSEO deploys a custom malware called MayaBot for command-and-control, system monitoring, and cryptocurrency mining, and also directs victims to tech support scam call centers.
Article analysis
Skim this article about "BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams": 3 key takeaways and more.
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
skim AI Analysis | The Hacker News
The Hacker News on BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams: skim's analysis surfaces 3 key takeaways. BengalSEO, a campaign operating from Rajasthan, India, uses sophisticated SEO poisoning techniques to promote malware (MayaBot) and tech support scams. Read the takeaways in seconds, then decide whether the full article is worth your time.
Category: Tech. News article analyzed by skim.
Summary
BengalSEO, a campaign operating from Rajasthan, India, uses sophisticated SEO poisoning techniques to promote malware (MayaBot) and tech support scams. The group leverages Black Hat SEO, traffic distribution systems, and legitimate hosting platforms to manipulate search results on Bing, tricking users into downloading malware or contacting scam centers.
Key Takeaways
- BengalSEO, a sprawling SEO poisoning campaign originating from Rajasthan, India, has been active since at least 2015, driven by IT service providers WeConnect Solutions LLC and Garage2Global.
- The campaign utilizes Black Hat SEO techniques, including backlinks, DOM injection, DOM shuffling, and keyword stuffing, to manipulate search engine rankings and promote malicious lure pages.
- BengalSEO deploys a custom malware called MayaBot for command-and-control, system monitoring, and cryptocurrency mining, and also directs victims to tech support scam call centers.
Statement Breakdown
- Claimed Facts: 70% of statements the article presents as facts
- Opinions: 20% of statements classified as editorial or subjective
- Claims: 10% of statements surfaced for additional reader evaluation
Credibility & Bias Reasoning
Credibility assessment: The article presents detailed technical analysis from cybersecurity researchers, citing specific tools, techniques, and infrastructure. It relies on a reputable source (The DFIR Report) for its findings, lending significant weight to its claims. The information is presented factually with minimal sensationalism.
Bias assessment: Technical Reporting. The article focuses on the technical aspects of a cybercrime campaign, detailing methods and tools used. It avoids emotional language or political commentary, presenting the information in a neutral, informative manner.
Note: This article provides a technical analysis of a cybercrime operation. While well-researched, readers should be aware that the subject matter involves complex technical details and ongoing threat landscapes.
Credibility flag: Technical Deep Dive
Claimed Facts (8)
- This is a factual statement about the existence and nature of the reported campaign.
- This provides a specific name and discovery date for the campaign.
- This states the operational origin, timeframe, and entities involved in the campaign.
- This describes the specific functionalities of the MayaBot malware.
- This provides a timeframe for the use of MayaBot by the group.
- This details the technical function of the Traffic Distribution System (TDS) and its use of Matomo.
- This describes the initial entry point and promotion method of the malicious pages.
- This lists specific Black Hat SEO techniques employed by the group.
Opinions (8)
- This statement presents a contrast between a company's stated services and the evidence found, implying a deceptive practice.
- The use of 'extensive' and 'multiple' suggests an interpretation of the group's capabilities rather than a purely objective measurement.
- The term 'sophisticated' is a qualitative judgment about the traffic distribution system.
- The phrase 'extensive knowledge' and 'dupe victims' are interpretive descriptions of the actor's skills and intent.
- The word 'suggests' indicates an interpretation of the observed data, and 'heavily relying' and 'artificially boost' are evaluative terms.
- While defining a technical term, the phrase 'with the goal of' attributes intent to the practice.
- The phrase 'allows...to appear unique' describes the perceived outcome and effectiveness of the technique.
- The phrase 'have also been found to install' implies a discovery and interpretation of the attackers' actions.
Claims (8)
- The title uses the word 'poisons' which is an emotionally charged and anthropomorphic term for a technical process.
- While impersonation is a factual description of the action, the context of 'decoy' and 'impersonate' leans towards a narrative framing.
- The word 'claim' suggests a potential for deception, framing the offerings as potentially false promises.
- The term 'hijacks' and 'bogus link' are strong, potentially sensationalized descriptors of the technical process.
- The term 'aggressive' is a subjective descriptor of the spamming technique.
- The word 'flooding' and the use of quotes around 'easily' and 'simple' can imply a manipulative or deceptive intent.
- This statement highlights a lack of definitive information, which could be a point of speculation or further investigation.
- The phrase 'ultimately push' suggests a hidden agenda, framing the activity as inherently deceptive.
Key Sources
- The DFIR Report — Cybersecurity Research Firm
- WeConnect Solutions LLC — IT Service Provider
- iConnect Soft Solutions LLC — Previous IT Service Provider
- Garage2Global — Website Design, SEO, and Digital Marketing Services Provider
- Microsoft Bing — Search Engine
- Matomo — Analytics Service
- Cloudflare — Web Infrastructure and Security Provider
- hCaptcha — Security Challenge Provider
- Google Tag Manager — Web Analytics Service
- Check Point Research — Cybersecurity Company
- The Hacker News — Cybersecurity News Outlet
This analysis was generated by skim (skim.plus), an AI-powered content analysis platform by Credible AI. Scores and classifications represent the platform's AI-generated assessment and should be considered alongside other sources.
skim analyzes recent The Hacker News coverage for what holds up, what reads as opinion, and what may not be fully supported. Last updated 8th September 2026.