BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
A sprawling search engine optimization (SEO) poisoning campaign, codenamed BengalSEO, has been operating since 2015 and is linked to two IT service providers, WeConnect Solutions LLC and Garage2Global. The campaign uses deceptive lure pages, promoted through Black Hat SEO techniques, to deliver malware (MayaBot) and tech support scams. The operation leverages a sophisticated traffic distribution system and employs legitimate hosting platforms like GitHub and Google Sites to maintain anonymity and boost search rankings. The threat actor, known as BengalSEO, relies heavily on backlinks and DOM shuffling to manipulate search engine results and has been linked to numerous GitHub accounts associated with Garage2Global. The campaign is part of a broader trend of SEO manipulation, as highlighted by Check Point Research's findings on a similar campaign targeting Brazilian government and educational institutions.
A sprawling search engine optimization (SEO) poisoning campaign, codenamed BengalSEO, has been operating since 2015 and is linked to two IT service providers, WeConnect Solutions LLC and Garage2Global. The campaign uses deceptive lure pages, promoted through Black Hat SEO techniques, to deliver malware (MayaBot) and tech support scams. The operation leverages a sophisticated traffic distribution system and employs legitimate hosting platforms like GitHub and Google Sites to maintain anonymity and boost search rankings. The threat actor, known as BengalSEO, relies heavily on backlinks and DOM shuffling to manipulate search engine ranking algorithms and artificially boost the visibility of the lure pages on search engine results.
One of the primary goals of BengalSEO is to create and promote a cluster of rogue lure pages that tie into a sophisticated traffic distribution system (TDS) to direct, track, and filter traffic to payloads and tech support scams. The TDS acts as a gating mechanism to lead victims to payload delivery domains through a redirector chain, while employing a legitimate privacy-first analytics service called Matomo for victim tracking and fingerprinting. The group utilizes extensive SEO and web development capabilities to create and promote a cluster of rogue lure pages with multiple Black Hat SEO techniques. These lure pages then tie into a sophisticated traffic distribution system to direct, track, and filter traffic to payloads and tech support scams.
Specifically, the TDS acts as a gating mechanism to lead victims to payload delivery domains through a redirector chain, while employing a legitimate privacy-first analytics service called Matomo for victim tracking and fingerprinting. The lure and landing pages come embedded with a Matomo tracking script to profile the browser on the client-side and send the information to the domain "stats.us3[.]org." A search for the domain "stats.us3[.]org" on urlscan.io yields 1,112 results as of writing, down from 1,190 at the time of analysis.
To avoid detection and replace domains that have been blocked or taken down, BengalSEO constantly rotates redirector domains and temporarily replaces them with legitimate URLs. The bulk of the BengalSEO infrastructure was registered around August 2025 and later, with heightened activity continuing through late 2025 and early 2026. The domains have been registered across .my, .shop, and .info top-level domains (TLDs).
DOM Shuffling, on the other hand, refers to the practice of dynamically reordering HTML elements using embedded JavaScript code with the goal of randomizing the Document Object Model (DOM) structure. This, in turn, allows identical setup guides deployed across hundreds of domains to appear unique to web crawlers and bypass spam filters. The lure and landing pages are constantly updated via commits to rotate redirector domains or temporarily replace them with legitimate URLs.
BengalSEO has been observed using legitimate web page hosting platforms such as GitHub.io, pages.dev, sites.google.com, and readthedocs.io to aid in their SEO poisoning efforts, likely weaponizing the trust and reputation of these services that factor into the search engine rankings. The DFIR Report said it also identified multiple BengalSEO-linked GitHub accounts that were used for developing and hosting lure pages. The decoy pages are constantly updated via commits to rotate redirector domains or temporarily replace them with legitimate URLs so as to avoid detection and replace domains that have been blocked or taken down.
As many as 84 active BengalSEO GitHub accounts have been detected between Jan 2024 and March 2026. Further examination of the commit history made by these accounts has uncovered email addresses linking them to Garage2Global domains ("wc[.]ci"). A sample of some of the GitHub accounts and their associated Garage2Global addresses is as follows:
- activate-uhc-com-ucard - [email protected]
- activate-uhc-helpbook - [email protected]
- capitalonecredit - [email protected]
- help-line-center - [email protected]
- snehajaing2g - snehajaing2g@gmail
The campaign is part of a broader trend of SEO manipulation, as highlighted by Check Point Research's findings on a similar campaign targeting Brazilian government and educational institutions since mid-2025. The activity has been attributed to a Chinese-speaking cybercrime cluster known as Gambling Goblin, which has ties to Earth Berberoka (aka GamblingPuppet), a threat actor known for singling out gambling websites across Asia since at least 2020. The group is "operating localized phishing networks in Portuguese, Vietnamese, Spanish, and English, while also maintaining infrastructure that generates new domains daily." The phishing pages pose as trusted app stores such as Google Play, Microsoft Store, and Amazon, leveraging the high-reputation domains to inflate search rankings and ultimately push online gambling and sports betting. The exact initial access route is unknown.
Between 2023 and 2026, BengalSEO primarily registered domains through Spaceship (47.6%) and Namecheap (28.6%). For hosting, the group heavily favored Cloudflare (81.1%) to proxy traffic, with Hostmaza serving as the origin host for 10.0% of domains. One account managing some of the redirector domains ("wapp[.]live") was suspended by Hostmaza earlier this year.
