DFIR Report uncovered BengalSEO, a search-poisoning cluster that has run from Rajasthan since at least 2015 and uses Bing results to push victims toward MayaBot malware or tech-support scams. It ties the operation to WeConnect Solutions LLC and Garage2Global, and says the group has used MayaBot since 2022.
The bait pages look like support portals, software downloads, or activation sites, but the page a user reaches is only the start. BengalSEO uses redirector chains, tracking, and browser fingerprinting to decide whether to send a visitor to malware delivery or a scam call center, which lets the operation hide from scanners and reputation filters that only judge the first link.
For organizations whose users search Bing for downloads or help, the exposure sits in the search-results layer itself: a trusted ranking can already be the attacker-controlled entry point. That makes the problem harder than a bad domain list, because the lure may sit on a reputable host while the payload page stays one step away.