BengalSEO Uses SEO Poisoning and MayaBot to Drive Malware and Tech-Support Scams

· Original article ↗

Summary

The DFIR Report details BengalSEO’s SEO-poisoning operation, which uses malicious lure pages and traffic filtering to deliver MayaBot malware or direct victims to tech-support scams.

Key points

  • The researchers attribute the operation, with high confidence, to individuals and IT service providers in Rajasthan, India, and say it has operated since at least 2015.
  • BengalSEO promotes fake support and software pages through search results, using black-hat SEO tactics to draw in victims.
  • A traffic distribution system uses rotating redirectors, browser fingerprinting, and CAPTCHA challenges to filter visitors and route selected victims to malicious pages.
  • Victims may download a ZIP containing a JavaScript dropper disguised as an executable; running it through wscript.exe initiates the custom MayaBot infection.
  • Some visitors are instead directed to pages urging them to call the operation’s tech-support scam centers.
  • The researchers link WeConnect Solutions and Garage2Global to the operation and identified 84 active related GitHub accounts between January 2024 and March 2026.

Article Details

Attack Vectors
  • BengalSEO promotes malicious lure pages through SEO poisoning, including backlink spam, keyword stuffing, DOM injection, and DOM shuffling.
  • Lure pages impersonate software support, downloads, and service activation portals and direct visitors through rotating TDS redirectors.
  • The TDS uses CAPTCHA challenges and browser fingerprinting to decide whether to serve a malicious landing page or a benign page.
  • Malicious landing pages offer ZIP downloads containing a MayaBot JavaScript dropper disguised as an EXE file. The dropper executes through wscript.exe when opened.
  • Some visitors are instead directed to pages prompting them to call a tech-support scam number.
Defensive Notes
  • The TDS can serve benign content when a visitor fails its checks, complicating automated inspection.
  • BengalSEO-linked GitHub repositories periodically rotate embedded redirector domains or temporarily replace them with legitimate URLs.
  • The report identifies shared Matomo tracking infrastructure across lure pages, landing pages, and some BengalSEO business websites.

Indicators of compromise

TypeIndicatorContext
DOMAIN4jio[.]comObserved TDS redirector routing visitors from lure pages.
DOMAINcus[.]camDomain identified as serving MayaBot C2.
DOMAINdll[.]latDomain identified as serving MayaBot C2.
DOMAINflosyr[.]comObserved TDS redirector routing visitors from lure pages.
DOMAINfm[.]ciObserved TDS redirector routing visitors from lure pages.
DOMAINlink72[.]comObserved TDS redirector embedded in multiple lure pages.
DOMAINpltechoo[.]proIdentified payload-delivery landing-page domain.
DOMAINpre[.]imObserved TDS redirector routing visitors from lure pages.
DOMAINq82[.]netObserved TDS redirector routing visitors from lure pages.
DOMAINreficon[.]proIdentified payload-delivery landing-page domain.
DOMAINu320[.]myIdentified payload-delivery landing-page domain.
DOMAINurl90[.]comObserved TDS redirector routing visitors from lure pages.
DOMAINus00[.]netObserved TDS redirector routing visitors from lure pages.
DOMAINus3[.]orgDomain registered for BengalSEO Matomo tracking infrastructure.
DOMAINus6[.]myObserved TDS redirector routing visitors from lure pages.
DOMAINus99[.]orgDomain identified as serving MayaBot C2.
DOMAINustechnio[.]comIdentified payload-delivery landing-page domain and first domain in a MayaBot SEO campaign series.
DOMAINustechnio100[.]comNamed endpoint of the sequential domain series featured in MayaBot SEO campaigns.
DOMAINwapp[.]liveBengalSEO-controlled domain whose subdomains were observed serving as redirectors.
DOMAINww0[.]usObserved TDS redirector routing visitors from lure pages.
HOSTNAMEactivate[.]uhc[.]comLure-page link promoted through forum profile spam.
HOSTNAMEajax[.]googleapis[.]com[.]coTyposquatted host constructed by lure-page JavaScript to fetch an SEO-poisoning HTML payload.
HOSTNAMEtax[.]dll[.]latIdentified payload-delivery landing-page domain.
HOSTNAMEto[.]ghredir[.]comObserved TDS redirector routing visitors from lure pages.
HOSTNAMEts[.]remdos[.]comObserved TDS redirector routing visitors from lure pages.
HOSTNAMEtx[.]newredir[.]comObserved TDS redirector routing visitors from lure pages.
HOSTNAMEtx[.]platdir[.]comObserved TDS redirector routing visitors from lure pages.
URLhxxps[:]//oculus-app[.]com/BengalSEO impersonation lure page identified in Matomo tracking data.
URLhxxps[:]//stats[.]us3[.]org/matomo[.]phpBengalSEO Matomo endpoint receiving tracking information and browser fingerprints.

MITRE ATT&CK

People

Threat Actors

Malware

Vendors

Products

Tools

Countries

Industries

Related Articles