BengalSEO Hijacks Bing Results to Spread Malware & Tech Support Scams

A newly uncovered campaign called BengalSEO has been manipulating Bing search results to push users toward custom malware installs—most notably MayaBot—and persistent tech support scams. Active since at least 2015, the operation appears centered in Rajasthan, India, and operating under two companies: WeConnect Solutions LLC (formerly iConnect Soft Solutions LLC) and Garage2Global. Researchers believe the latter, though outwardly offering web design and marketing, builds the malicious infrastructure powering this deception.

How BengalSEO’s Engines of Deception Operate

At the core of BengalSEO’s strategy are lure pages, which impersonate legitimate portals for streaming services, activation tools, or antivirus software to mislead users via search. Using Black Hat SEO tricks—like keyword stuffing, DOM injection/shuffling, backlink farms, and aggressive user-generated content spam—the group ensures these decoy pages rank highly in Bing searches. Common tricks involve forums and comment spam leading to domains like “viziocomsetupentercode.github[.]io” tied to over 2,000 backlinks from 167 different external domains in one example.

Traffic is managed by a Traffic Distribution System (TDS). This includes a redirector chain to funnel users based on fingerprinting, often cloaked with privacy-first analytics such as Matomo, and challenges like those offered by Cloudflare Turnstile or hCaptcha to block bots. Final destinations vary: users may download a ZIP file carrying MayaBot malware, or be duped into calling a fake support number claiming some security issue.

Inside MayaBot and the Enrollment Tactics

MayaBot, used since around 2022, supports remote command-and-control, system monitoring, and installs the XMRig crypto miner. The infection starts with what seems to be an innocent installer; inside the ZIP—which often mimics trusted software—is a JavaScript dropper. When run via “wscript.exe”, it unleashes MayaBot and its malicious activities under the guise of legitimate operations.

In some cases, no malware is delivered—but that doesn’t make them any less dangerous. These alternate landing pages push users to call scam numbers, citing suspicious account activity or linking the issue to services like Bitdefender Central. Meanwhile, the backend infrastructure includes dozens of GitHub-hosted pages, rotating redirector domains, frequent updates, and domain registrations through Namecheap and Spaceship. The majority of domains proxy through Cloudflare, bringing additional layers of obfuscation.

Broader System and Takeaways

BengalSEO isn’t a fly-by-night operation. Between Jan 2024 and March 2026 alone, researchers identified 84 active GitHub accounts tied to it. Domains appear across TLDs like .my, .info, and .shop, with registrations ramping up in mid-to-late 2025. Cloudflare is used in ~81% of them to hide origin hosts; for origins, small providers like Hostmaza constitute ~10%. The scale of the SEO poisoning is notable both in volume and sophistication.

This activity shows growing confidence by cybercriminal operations in manipulating legitimate platforms and rankings to spread malware and fraud. Readers should beware of high-ranking links that lead to soft download portals, be cautious of structures like ZIP packages tied to executables, and think twice before calling unverified support numbers. Browser fingerprinting, analytics scripts embedded in apparent trusted sites, and randomized page content are especially red flags.

As search engines and hosting platforms scramble to tighten defenses, BengalSEO serves as a reminder: SEO manipulation is no longer low-skill or low-stakes. If it’s ranking high—even for trusted services’ names—it may be precisely because bad actors have engineered it that way.

What this means: The line between legitimate-seeming results and malicious content is being blurred. As operations like BengalSEO evolve, it underscores the urgency for tighter vetting by platform providers, faster takedowns of rogue domains, and awareness among users. Watching how Microsoft and firms in the SEO/hosting ecosystem respond will be crucial to preventing the next wave of search-engine borne malware campaigns.