Full Report
Key Takeaways The DFIR Report Offerings Check out our Products here and our Services here. Want a demo, more information on our services, pricing or just want to chat? Get in Touch Contact us today for pricing or a demo! Case Summary In March 2026, our team identified an SEO poisoning campaign leading to malware deployment […] The post BengalSEO Part 1: Anatomy of the Operation appeared first on The DFIR Report.
Analysis Summary
# Incident Report: BengalSEO SEO Poisoning & Malware Operation
## Executive Summary
In March 2026, a sophisticated SEO poisoning campaign dubbed "BengalSEO" was identified, originating from a scam operation based in Rajasthan, India. The threat actors utilized advanced black-hat SEO techniques and a custom Traffic Distribution System (TDS) to drive users toward tech support scams and a custom malware strain named "MayaBot." The operation was traced back to two specific IT service providers and their owners, highlighting a professionalized approach to malware deployment and cyber-scamming.
## Incident Details
- **Discovery Date:** March 2026
- **Incident Date:** Ongoing (active activity identified from 2023 through 2026)
- **Affected Organization:** Multiple (Widespread campaign targeting general internet users)
- **Sector:** Cross-sector (General Public/Web Users)
- **Geography:** Attacker origin: Rajasthan, India; Victims: Global
## Timeline of Events
### Initial Access
- **Date/Time:** March 2026 (Initial detection of the campaign)
- **Vector:** SEO Poisoning (Search Engine Results)
- **Details:** The actors created and promoted malicious lure pages using extensive SEO and web development capabilities to rank highly in search engine results.
### Lateral Movement
- **Details:** As this report focuses on the "Anatomy of the Operation" (Part 1), specific internal network lateral movement was not the primary focus; rather, the focus was on the movement of traffic from search engines through a Traffic Distribution System (TDS) to the final payload.
### Data Exfiltration/Impact
- **Details:** Deployment of MayaBot malware and redirection of users to Tech Support Scam pages designed to defraud users and gain persistent access to their systems.
### Detection & Response
- **How it was discovered:** Identification by The DFIR Report team through monitoring of SEO poisoning campaigns and malware deployment patterns.
- **Response actions taken:** Attribution analysis identifying two IT service provider companies in India and their owners; cataloging of custom malware (MayaBot).
## Attack Methodology
- **Initial Access:** SEO Poisoning (Black Hat SEO techniques to rank lure pages).
- **Persistence:** MayaBot malware deployment (custom strain).
- **Defense Evasion:** Use of a sophisticated Traffic Distribution System (TDS) to filter and direct traffic, likely to avoid automated crawlers and security researchers.
- **Discovery:** Web-based reconnaissance via user search queries.
- **Lateral Movement:** N/A (External-to-victim delivery).
- **Collection:** User information via tech support scam interactions and malware data gathering.
- **Exfiltration:** N/A (Focus on fraud and payload delivery).
- **Impact:** Financial fraud via tech support scams and system compromise via MayaBot.
## Impact Assessment
- **Financial:** High (Large-scale scam operation targeting numerous victims).
- **Data Breach:** Compromise of individual user systems via MayaBot.
- **Operational:** Disruption to individual users and potential resource drain for organizations whose keywords were targeted.
- **Reputational:** High for the identified IT Service Provider companies involved in the scam.
## Indicators of Compromise
- **Network indicators:** Indicators involve the Traffic Distribution System (TDS) nodes and lure page domains (specific domains available in the linked GitHub repository).
- **File indicators:** MayaBot malware samples (hashes provided in the full report repository).
- **Behavioral indicators:** Redirection from search engine results to tech support "alert" pages or unauthorized MayaBot binary downloads.
*Full IOC list available at: hxxps[:]//github[.]com/The-DFIR-Report/DFIR-Report-Indicators/blob/main/2026-08-24-bengalseo-part-1-anatomy-of-the-operation[.]md*
## Response Actions
- **Containment measures:** Identification and public disclosure of the infrastructure used by BengalSEO.
- **Eradication steps:** Documentation of MayaBot to assist antivirus vendors in creating signatures.
- **Recovery actions:** Reporting of malicious domains to registrars and hosting providers.
## Lessons Learned
- **Key takeaways:** Scam operations are increasingly professionalized, often operating under the guise of legitimate IT service providers.
- **What could have been done better:** Enhanced monitoring of search engine results for high-value keywords could potentially flag these lure pages before they gain significant traffic.
## Recommendations
- **Prevention:** Implement browser-based protection tools that block known malicious TDS and scam domains.
- **Training:** Conduct user awareness training regarding "Tech Support" pop-ups and the risks of downloading files from non-official search results.
- **Detection:** Utilize web filtering solutions to block traffic to newly registered or suspicious domains identified in the BengalSEO IOC list.