# The Rise of SEO Poisoning: How Cybercriminals Are Weaponizing Search Engines to Deploy Malware
In recent findings that have alarmed the cybersecurity community, a large-scale operation has been uncovered that leverages search engine optimization as a weapon to distribute malware and run elaborate tech support scams. The campaign, which has been active since at least 2015, represents a growing trend where legitimate-looking web infrastructure is hijacked to manipulate search rankings and funnel unwitting users toward malicious payloads.
## Understanding the BengalSEO Operation
The campaign, tracked under the name BengalSEO, originated from operations based in the Indian state of Rajasthan. At the center of this operation are two IT service firms — WeConnect Solutions LLC (formerly known as iConnect Soft Solutions LLC) and Garage2Global — that ostensibly provide website design and digital marketing services. However, investigators have found compelling evidence that Garage2Global has been building and managing the malicious web infrastructure necessary for large-scale SEO poisoning.
What makes this campaign particularly insidious is its technical sophistication. The operators employ a variety of illegal or manipulative search optimization strategies — commonly referred to as Black Hat SEO — to push fake technical support and software activation pages to the top of search results. Victims searching for legitimate software downloads or tech support solutions are instead led to decoy pages that mimic trusted portals.
These lure pages are designed to impersonate well-known services, including streaming platform support centers, antivirus software gateways, gaming software distributors, and even tax preparation and healthcare activation portals. A notable example involved hijacking search queries related to Bitdefender login pages, redirecting users through a chain of intermediary domains before serving the final malicious content.
## The Malware Component: How Victims Get Infected
At the heart of BengalSEO’s payload delivery system sits a custom piece of malware called MayaBot. Active since 2022, MayaBot serves multiple purposes depending on the operator’s goals — it establishes command-and-control communication channels, monitors the compromised system, and can deploy cryptocurrency mining software such as XMRig.
The infection typically begins when a user clicks what appears to be a legitimate download button on a fake software page. This triggers the download of a ZIP archive containing a JavaScript-based dropper disguised as an executable installer. Once executed through the Windows Script Host process, MayaBot silently establishes a foothold on the victim’s machine.
In some instances, rather than delivering malware, the final landing pages direct users to a phone number belonging to the scam operators, posing as technical support representatives who claim the user’s account has been compromised. These social engineering tactics are designed to extract personal information and payments from victims.
## The Traffic Distribution System Behind the Scheme
A key element of BengalSEO’s success is a sophisticated traffic distribution system (TDS) that manages every stage of the victim’s journey from search result to final destination. The TDS acts as a filtering gate, using challenges like Cloudflare Turnstile and hCaptcha to block automated security scanners and legitimate web crawlers while allowing real users through.
Victim tracking and fingerprinting are handled through analytics services, with the operators using Matomo in many cases and Google Tag Manager on pages hosted on platforms like GitHub Pages. By profiling each visitor’s browser and device characteristics, the TDS ensures that each user receives a tailored landing experience — whether that means serving malware, redirecting them to a scam call center, or showing a legitimate-looking software page to maintain the deception.
To maintain their dominance in search rankings, BengalSEO floods forums and comment sections with artificial backlinks at massive scale. The decoy pages are interconnected across hundreds of domains, creating an elaborate web of cross-references that tricks search engines into ranking them as credible sources of information.
## Hosting Infrastructure and Domain Strategy
The operators behind BengalSEO have shown remarkable resourcefulness in selecting hosting platforms. They favor trusted services such as GitHub Pages, Google Sites, Read the Docs, and Vercel Pages — platforms that carry inherent legitimacy and are less likely to be flagged by security tools or browsers.
Domain registrations have been spread across multiple registrars, with Spaceship and Namecheap accounting for the majority. Top-level domains used include .my, .shop, and .info — choices that help mask the true nature of the infrastructure. For Traffic proxying, over 80% of operational domains rely on Cloudflare, which provides both anonymity and reliability for the campaign’s redirector network.
Between January 2024 and March 2026, cybersecurity researchers identified approximately 84 active GitHub accounts linked to BengalSEO operations, many of which contained email addresses traceable to Garage2Global. These accounts are continuously updated to rotate redirector domains, replace compromised servers, and adjust the campaign infrastructure as needed to evade takedown efforts.
## A Broader Pattern of Abuse
The BengalSEO campaign is not an isolated incident. Cybersecurity firms have documented similar patterns of search engine manipulation being used at global scale. In a separate but related development, a campaign targeting Brazilian government and educational institutions since mid-2025 has demonstrated how compromised websites can be transformed into SEO engines that push phishing content and malware distribution pages.
This broader threat landscape underscores a critical vulnerability in the modern internet ecosystem. As search engines remain the primary gateway through which users access online resources, the integrity of search results becomes a matter of cybersecurity. When bad actors can manipulate what appears at the top of search results, they gain access to the most valuable real estate on the internet — the first page of results that users trust and click on without hesitation.
## FAQ
**What is SEO poisoning?**
SEO poisoning — also known as search engine poisoning or Black Hat SEO — is the practice of manipulating search engine rankings to push malicious or fraudulent web pages to the top of search results. Attackers use techniques like keyword stuffing, link spamming, and content injection to make their pages appear legitimate and relevant to users’ search queries.
**How does BengalSEO differ from other cybercrime campaigns?**
BengalSEO stands out for its combination of technical complexity and scale. It integrates a full-stack infrastructure that includes fake websites, automated traffic distribution systems, real-time browser fingerprinting, malware deployment capabilities, and social engineering operations — all orchestrated through a coordinated network of accounts and domains.
**Who is most at risk from these scams?**
Anyone who relies on search engines to find software downloads, technical support, or online services can fall victim. However, individuals searching for well-known software like antivirus tools, streaming services, or system utilities are particularly targeted because their search intent aligns with the bait pages created by the attackers.
**Can I protect myself from these attacks?**
Yes. Users should verify the legitimacy of websites before downloading software, avoid clicking on manipulated search results that appear slightly off from expected URLs, and use reputable security tools that warn about known malicious domains. Keeping browsers and operating systems updated also helps mitigate many attack vectors.
**What role do legitimate hosting platforms play in enabling these campaigns?**
Free and widely trusted hosting services are attractive to attackers because they provide immediate credibility. Search engines tend to trust domains hosted on well-known platforms, giving malicious pages an advantage in ranking. Additionally, some platforms may lack the content moderation infrastructure needed to detect abusively created accounts at scale.
**Are tech support scams connected to BengalSEO?**
Yes. In addition to deploying malware, BengalSEO lures users into calling fraudulent phone lines where they are tricked into paying for unnecessary “technical support services.” This dual approach — combining malware distribution with social engineering — maximizes the campaign’s financial return.
**What are the common indicators that a website may be part of an SEO poisoning campaign?**
Warning signs include URLs hosted on unexpected platforms, excessive use of generic or aggressively SEO-optimized language, requests to download software from unusual file formats like JavaScript disguised as executables, and pressure tactics such as urgency warnings about account compromise.
## Conclusion
The BengalSEO operation exemplifies how cybercrime has evolved beyond simple phishing or malware distribution into a full-scale industry with specialized components — traffic management, search manipulation, browser fingerprinting, and social engineering — all integrated into a seamless fraudulent ecosystem. The campaign highlights a troubling reality: the tools that make the modern internet accessible and useful are equally powerful in the hands of those who seek to exploit them.
As search engines continue to evolve their ranking algorithms and security teams develop more advanced detection methods, the perpetrators behind schemes like BengalSEO are likely to adapt, shifting their infrastructure to new platforms and developing even more sophisticated evasion techniques. The ongoing battle between cybercriminals and defenders is unlikely to slow down in the foreseeable future.
For internet users, the best defense remains a combination of vigilance, awareness of how search rankings can be manipulated, and the use of comprehensive security solutions that provide real-time protection against both malicious downloads and fraudulent websites.
Thank you for reading



