BengalSEO Poisons Bing Search Results
The BengalSEO campaign, active since 2015, manipulated Bing search results to deliver MayaBot malware and tech support scams. Discovered by DFIR Report in March 2026, the campaign poisoned the information supply chain of the AI-driven search engine. Users searching for legitimate software were redirected to malicious sites. Two IT service providers were implicated.
Severity: Critical · Category: Supply Chain
Impact: Deployment of MayaBot malware and facilitation of tech support scams via manipulated search results.
Source: The Hacker News · Sep 08 2026 · Original source
What Happened
A widespread search engine optimization (SEO) poisoning campaign, codenamed BengalSEO, was discovered by the DFIR Report in March 2026. This campaign has been operational since at least 2015, originating from Rajasthan, India, and is linked to two IT service providers: WeConnect Solutions LLC (formerly iConnect Soft Solutions LLC) and Garage2Global. Garage2Global, despite claiming to offer legitimate web design and SEO services, was found to develop malicious web infrastructure used in these SEO poisoning efforts.
The campaign leverages extensive SEO and web development capabilities to create and promote rogue lure pages using various Black Hat SEO techniques. These lure pages are designed to appear at the top of Microsoft Bing search results, impersonating legitimate technical support and service activation portals for streaming services, or offering downloads for antivirus tools, gaming software, and taxation utilities, as well as claiming to activate credit, healthcare, and gift cards. An example involved hijacking searches for "bitdefender central how to login" to serve a fraudulent link.
Upon clicking a prominent "Get Started" button on a lure page, unsuspecting users are routed through a series of redirector domains that fingerprint their web browser. This sophisticated traffic distribution system (TDS) then directs them to a final landing page. This page either provides a download link for fake software, which contains a JavaScript dropper for custom malware dubbed MayaBot, or redirects the victim to a contact page instructing them to call a BengalSEO scam number for purported suspicious activity.
Timeline
- 2015 — BengalSEO campaign operating since at least this year.
- 2022 — BengalSEO leveraged MayaBot since this year.
- 2023-2026 — BengalSEO primarily registered domains through Spaceship (47.6%) and Namecheap (28.6%).
- Jan 2024 - March 2026 — As many as 84 active BengalSEO GitHub accounts were detected.
- August 2025 — The bulk of the BengalSEO infrastructure was registered around this time and later.
- Late 2025 - Early 2026 — Heightened activity of BengalSEO infrastructure continued.
- Earlier this year (2026) — Hostmaza suspended one account managing some of the redirector domains.
- March 2026 — The BengalSEO campaign was discovered by the DFIR Report.
- Late August 2026 — The DFIR Report published a technical analysis of the campaign.
Technical Analysis
The financially motivated threat actor behind BengalSEO demonstrates extensive knowledge of black hat SEO techniques and web development. These techniques include backlinks, DOM injection, DOM shuffling, and keyword stuffing. The group employs aggressive user-generated content (UGC) spam to generate backlinks at scale, flooding forums and comment sections with hyperlinks to lure pages. For instance, a Vizio decoy page was found to have 2,000 backlinks and 167 unique external domains linking to it.
DOM Shuffling is utilized to dynamically reorder HTML elements using embedded JavaScript code, randomizing the Document Object Model (DOM) structure. This allows identical setup guides deployed across hundreds of domains to appear unique to web crawlers, thereby bypassing spam filters. The campaign integrates a sophisticated traffic distribution system (TDS) that acts as a gating mechanism, directing victims through a redirector chain to payload delivery domains. This TDS also handles traffic flow, campaign performance, and cloaking, and employs legitimate privacy-first analytics services like Matomo for victim tracking and fingerprinting. Before serving the main payload page, TDS-based redirector domains display Cloudflare Turnstile or hCaptcha challenges to screen automated scanners, crawlers, and bots. Lure and landing pages embed a Matomo tracking script to profile the browser client-side, sending information to the domain "stats.us3[.]org." Other analytics services, such as Google Tag Manager, are used on hosting platforms like github.io and pages.dev.
The final landing pages either deliver a ZIP archive containing a JavaScript dropper for MayaBot, which masquerades as an executable and is executed via "wscript.exe," or redirect victims to scam call centers. BengalSEO leverages legitimate web page hosting platforms such as github.io, pages.dev, sites.google.com, and readthedocs.io, weaponizing their trust and reputation to boost search engine rankings. Multiple BengalSEO-linked GitHub accounts were identified, used for developing and hosting lure pages, with decoy pages constantly updated via commits to rotate redirector domains or temporarily replace them with legitimate URLs to avoid detection. Further examination of commit history linked these accounts to Garage2Global domains. The bulk of the BengalSEO infrastructure was registered around August 2025 and later, with heightened activity through late 2025 and early 2026, across .my, .shop, and .info top-level domains. For domain registration, Spaceship (47.6%) and Namecheap (28.6%) were primarily used between 2023 and 2026, while Cloudflare (81.1%) was heavily favored for proxying traffic, with Hostmaza serving as the origin host for 10.0% of domains.
Impact
The BengalSEO campaign resulted in the deployment of custom MayaBot malware, which facilitates command-and-control (C2), system monitoring, and the delivery of an XMRig cryptocurrency miner to affected systems. Additionally, the campaign successfully duped victims into calling scam call centers, leading to potential financial exploitation through tech support scams. The campaign's manipulation of Microsoft Bing search results caused fraudulent links to appear at the top of search queries, misleading users searching for legitimate technical support, streaming services, antivirus tools, gaming software, taxation utilities, or credit, healthcare, and gift card activation. The threat actor is financially motivated. The scale of the SEO poisoning is indicated by examples such as a Vizio decoy page having 2,000 backlinks and 167 unique external domains. The tracking domain "stats.us3[.]org" yielded 1,112 results on urlscan.io at the time of reporting, down from 1,190 during the initial analysis.
Discovery & Response
The sprawling SEO poisoning campaign was discovered by the DFIR Report in March 2026. The DFIR Report subsequently published a detailed technical analysis of the campaign in late August 2026. In response to the malicious activity, Hostmaza suspended one account earlier in 2026 that was managing some of the redirector domains, specifically "wapp[.]live." The BengalSEO group actively updates its decoy pages via commits to rotate redirector domains or temporarily replace them with legitimate URLs, aiming to avoid detection and replace domains that have been blocked or taken down.
How Fencio prevents this
The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.
Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.