BengalSEO SEO Poisoning and MayaBot Malware Campaign
Score: 8/10

BengalSEO SEO Poisoning and MayaBot Malware Campaign

The BengalSEO group, linked to WeConnect Solutions and Garage2Global, utilizes sophisticated SEO poisoning and a custom Traffic Distribution System (TDS) to deploy MayaBot malware and tech support scams.

Executive Summary

In March 2026, the DFIR Report identified a widespread search engine optimization (SEO) poisoning campaign attributed to a group dubbed BengalSEO, operating out of Rajasthan, India. The operation is driven by two business entities, WeConnect Solutions LLC (a tech support call center) and Garage2Global (a digital marketing provider), which utilize their legitimate web development infrastructure to promote malicious lure pages for financial gain.

The attack chain involves highly optimized lure pages that impersonate popular brands like Bitdefender, TurboTax, and Hulu to capture search traffic. Victims are funneled through a sophisticated Traffic Distribution System (TDS) that uses rotating redirectors and Matomo analytics to fingerprint browsers and filter automated scanners. The final payload is typically custom MayaBot malware or a prompt to call a fraudulent tech support number.

This campaign represents a significant threat to consumer and corporate users alike due to the group's nearly decade-long history of refining Black Hat SEO techniques. The integration of custom malware (MayaBot) with high-volume SEO capabilities marks an evolution from simple tech support scams to persistent endpoint compromise targeting multiple sectors including financial services and retail.

Key Details

Threat Name

BengalSEO MayaBot Campaign

Affects

—

Adversary

BengalSEO Other Adversaries and Aliases: WeConnect Solutions LLC; Garage2Global

Malware/Tools

MayaBot, XMRig

Report Score

8out of 10
Quality Score
Good
IOC Quality10
TTP Details9
Detection Guidance5
Enterprise Relevance6
Clarity & Structure8
Technical Depth9

Sources