The DFIR Report has published an analysis of a sprawling search engine poisoning operation it calls BengalSEO, run from the Indian state of Rajasthan by two firms it links to malicious web infrastructure, WeConnect Solutions and Garage2Global. The group has operated since at least 2015 and has leaned on MayaBot, a custom backdoor that adds command-and-control, system monitoring, and an XMRig cryptocurrency miner, since 2022.
The operation saturates Bing with decoy pages styled as support and activation portals for streamers, antivirus vendors, games and tax tools. Black-hat tactics include backlink spam, keyword stuffing, DOM injection, and DOM shuffling, which randomizes page structure so cloned setups look unique to crawlers and filters. In one case, a search for a Bitdefender sign-in phrase lands on a fake page parked at readthedocs[.]io.
A traffic distribution system gates visitors with Cloudflare Turnstile or hCaptcha challenges to filter out bots and researchers before redirecting victims through fingerprinting stages to the final payload page. Tracking runs through Matomo analytics beacons, with more than 1,100 public sightings of the stats.us3[.]org collector domain at the time of analysis.
Hit download and a ZIP arrives while the page bounces to the real software vendor 40 seconds later, a ruse that keeps the act convincing. Defenders should treat lookalike support domains, unexpected installer downloads, and search ads promising activation codes as the primary warning signs.
