"This group utilizes its extensive SEO and web development capabilities to create and promote lure pages with multiple Black Hat SEO techniques," the DFIR Report said, describing a long-running operation that has been manipulating Microsoft Bing search results to funnel victims toward malware and tech-support scams.
How the SEO poisoning works
DFIR Report’s analysis lays out a deliberate, multi-stage abuse of search-engine visibility. The campaign — codenamed BengalSEO and active from at least 2015 — builds networks of malicious “lure” pages that impersonate legitimate support or activation portals (for example, a page hijacking searches for "bitdefender central how to login"). Those lure pages are promoted through aggressive black-hat SEO techniques: backlinks and large-scale user-generated content (UGC) spam, DOM injection, DOM shuffling to randomize page structure, and keyword stuffing. One Vizio decoy page had about 2,000 backlinks from 167 unique external domains, a pattern DFIR treats as evidence the group relies on backlink volume to game ranking algorithms.
Traffic distribution and fingerprinting: the TDS and analytics
BengalSEO ties lure pages into a traffic distribution system (TDS) that gates and directs visitors through chains of redirector domains. The redirectors use Cloudflare Turnstile or hCaptcha challenges to filter out automated scanners, crawlers and bots. Client-side profiling is performed with the legitimate analytics product Matomo; DFIR found Matomo scripts sending fingerprinting data to the domain "stats.us3[.]org" (urlscan.io showed 1,112 results for that domain at the time of reporting, down from 1,190 earlier).
The TDS both routes visitors to payload-delivery domains and serves as an operational control: it tracks campaign performance, fingerprints browsers to decide whether to deliver malware or a scam, and cloaks malicious intent until a human target reaches the final landing page.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadMayaBot and the final-stage delivery
At the end of some redirection chains are landing pages with a “Download for Windows” button that delivers a ZIP archive. Inside the archive DFIR found a JavaScript dropper that masquerades as the expected program; the dropper runs via "wscript.exe" and installs a custom malware the researchers call MayaBot. DFIR traces BengalSEO’s use of MayaBot back to 2022 and attributes to it command-and-control functionality, system monitoring, and the capability to deliver an XMRig cryptocurrency miner. In other cases, the final pages instead redirect victims to contact pages that instruct them to call a BengalSEO-operated scam number to resolve purported account issues.
DFIR listed example payload-delivery domains used in the campaign, including ustechnio[.]com, tax.dll[.]lat, u320[.]my, reficon[.]pro, ñ[.]link and pltechoo[.]pro.
Infrastructure, accounts, and the actors DFIR links to BengalSEO
DFIR says the operation has operated out of Rajasthan and identified two IT service providers involved: WeConnect Solutions LLC (formerly iConnect Soft Solutions LLC) and Garage2Global. Although Garage2Global promotes itself as a website design, SEO and digital marketing provider, DFIR found evidence it develops malicious web infrastructure used by the BengalSEO cluster. DFIR’s report ties many of the operation’s GitHub accounts (84 active accounts were detected between January 2024 and March 2026) to Garage2Global email addresses in the "wc[.]ci" domain. Sample GitHub account names and associated email strings cited by DFIR include activate-uhc-com-ucard (archi.jaing.2g@gmail.com), activate-uhc-helpbook (kamre@wc.ci), capitalonecredit (gracyurvashi36g2g@gmail.com), help-line-center (janvig2g@gmail.com) and snehajaing2g (snehajaing2g@gmail).
DFIR also documented registration and hosting patterns: many domains were registered beginning around August 2025 with heightened activity through late 2025 and early 2026, primarily across .my, .shop and .info TLDs. Between 2023 and 2026, 47.6% of BengalSEO-registered domains used Spaceship and 28.6% used Namecheap; Cloudflare proxied 81.1% of domains while Hostmaza served as origin host for 10.0% (DFIR noted one Hostmaza account managing redirector domains like "wapp[.]live" had been suspended earlier this year). The group also adopted legitimate hosting platforms — github.io, pages.dev, sites.google.com, readthedocs.io — to leverage their trust for search-ranking advantage.
What this means for technologists and hosting platforms, and end users
- Technologists and security teams: DFIR’s findings highlight a TDS-backed, analytics-driven delivery chain that mixes benign services (Matomo, Cloudflare, GitHub Pages) with malicious intent; defenders should prioritize detection of redirector chains, ZIP-contained droppers executed via "wscript.exe," and patterns of mass backlinking and DOM manipulation.
- Hosting platforms and registrars: the campaign’s use of github.io, pages.dev, readthedocs.io and similar services to host lure pages — plus evidence of mass commits used to rotate domains and evade takedown — points to a need for closer monitoring and faster takedown coupling with registrars and CDNs identified in DFIR’s domain registration statistics.
- End users: searches that surface technical-support or activation pages should be treated cautiously; DFIR shows some searches — for example, for Bitdefender Central login guidance — were routed to readthedocs-hosted decoys with “Get Started” buttons that initiated the redirection chain.
DFIR’s report paints BengalSEO as a mature, modular operation that blends SEO manipulation, analytics-driven gating and custom malware delivery. The specificity of domains, account ties and hosting-pattern statistics gives defenders concrete signals to hunt on — and leaves a clear question for platforms and registrars: will those signals be used to disrupt the redirector chains before more victims encounter MayaBot or the phone-based scams?
https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html




