DFIR Report identified BengalSEO, a Rajasthan-based scam operation that has used SEO poisoning, malicious lure pages, and a traffic distribution system to deliver the MayaBot malware and drive tech support fraud since at least 2015. The campaign relies on companies such as WeConnect Solutions LLC and Garage2Global, along with infrastructure spanning GitHub, Hostmaza, Cloudflare, Matomo, and numerous redirector and payload domains. #BengalSEO #MayaBot #WeConnectSolutionsLLC #Garage2Global #Hostmaza #Cloudflare #Matomo
Keypoints
- BengalSEO is a long-running scam operation based in Rajasthan, India, attributed with high confidence to core individuals and IT service providers.
- The group uses SEO poisoning and fake support or activation pages to push victims into either downloading malware or calling scam phone numbers.
- WeConnect Solutions LLC and Garage2Global were identified as key business entities driving the operation, with shared ownership and infrastructure links.
- BengalSEO built a custom malware loader/droplet named MayaBot, which has been used since 2022 to support scam activity.
- A custom traffic distribution system routes visitors through rotating redirector domains, captcha checks, and browser fingerprinting before serving payloads or benign decoys.
- The campaign leverages Matomo, Google Tag Manager, GitHub, and multiple hosting/registration providers to track visitors, host lure pages, and rotate infrastructure.
- Research uncovered hundreds of related domains, SSL certificates, subdomains, and GitHub accounts tied to BengalSEO activity from 2023 through 2026.
MITRE Techniques
- [T1036 ] Masquerading ā The group disguises fake support pages, fake software downloads, and a JavaScript dropper as legitimate tools or files [āThe lure pages mimic legitimate technical support and service activation portalsā / āInside the ZIP file is a MayaBot JavaScript dropper masquerading as an exe file.ā]
- [T1566 ] Phishing ā Victims are lured through deceptive support and activation pages that push them toward scams or malicious downloads [āmimic legitimate technical support and service activation portalsā / ātrick victims into calling their scam call centersā]
- [T1583.001 ] Acquire Infrastructure: Domains ā BengalSEO registers and uses large numbers of domains for redirectors, lure pages, landing pages, and payload hosting [āBetween 2023 and 2026, our team identified hundreds of domains and SSL certificates tied to BengalSEO.ā]
- [T1583.006 ] Acquire Infrastructure: Web Services ā The operation uses GitHub, pages.dev, github.io, readthedocs.io, and other web hosting services to publish lure infrastructure [āBengalSEO utilizes page hosting platforms such as github.io, pages.dev. sites.google.com, and readthedocs.io.ā]
- [T1587.001 ] Develop Capabilities: Malware ā The group built a custom malware strain, MayaBot, to support scam operations [āThis includes deploying a custom malware strain our team has named MayaBotā]
- [T1027 ] Obfuscated Files or Information ā JavaScript, URLs, and payloads are obfuscated or encoded to hide their purpose and evade detection [āobfuscated ASCII character codesā / āBase62 or base64 encodingā / āObfuscated MayaBot JavaScript dropper sourceā]
- [T1071.001 ] Application Layer Protocol: Web Protocols ā The campaign uses HTTP GET/POST, redirects, and web-based tracking to move victims through the delivery chain [āthe redirector server issues an HTTP 302 redirectā / āHTTP POST request to stats.us3[.]org/matomo.phpā]
- [T1090.003 ] Proxy: Multi-hop Proxy ā Traffic is routed through rotating redirector domains to hide final destinations and distribute victims [āusing a rotating network of redirector domains to route victims from lure pages to final landing pagesā]
- [T1497.001 ] Virtualization/Sandbox Evasion: System Checks ā Captcha challenges and browser fingerprinting are used to filter out automated analysis and bots [ādeploy a Cloudflare Turnstile or hCaptcha challenge to filter out automated crawlers, scanners, and botsā]
- [T1057 ] Process Discovery ā The payload execution path references wscript.exe, which executes the JavaScript dropper [āthe JavaScript executes via wscript.exe and initiates the Mayabot infectionā]
- [T1204.002 ] User Execution: Malicious File ā Victims are instructed to download and open a ZIP archive containing the malicious dropper [āthe victim begins downloading a ZIP archiveā / āprompted with instructions to open and execute the contents of the downloaded ZIP fileā]
- [T1105 ] Ingress Tool Transfer ā The lure-to-payload chain delivers malicious content from hosted landing pages to victim systems [ādeliver the MayaBot malwareā / āserving payloads to final landing pagesā]
- [T1568.002 ] Dynamic Resolution: Domain Generation Algorithms ā While not a classic DGA, the operation heavily rotates numbered and patterned domains across many TLDs to continually refresh infrastructure [ābulk domains using numbered us, act, and pc naming conventions across .my, .shop, and .info TLDsā]
Indicators of Compromise
- [Domains ] redirector and tracking infrastructure ā ts.remdos[.]com, tx.newredir[.]com, and 12 more redirector domains
- [Domains ] analytics and telemetry ā stats.us3[.]org, wapp[.]live, and other related subdomain infrastructure
- [Domains ] payload delivery and landing pages ā ustechnio[.]com, tax.dll[.]lat, and 4 more payload domains
- [Domains ] business and supporting sites tied to BengalSEO ā wc[.]ci, garage2global[.]com, and other associated domains
- [IP Addresses ] hosting and infrastructure resolution ā 5.101.140[.]80, plus other infrastructure-linked IPs referenced via DNS pivots
- [File/Script Names ] tracking and payload artifacts ā matomo.js, bootstrap-table.min.css, and the MayaBot JavaScript dropper
- [Hosting/Service Platforms ] infrastructure used for lure pages and analysis ā github.io, pages.dev, readthedocs.io, and other hosting services
- [SSL/TLS Certificates / Subdomains ] certificate and subdomain pivots ā 411 subdomains for wapp[.]live, 80 for aol[.]cx, and 43 for iconnectpc[.]com
Read more: https://thedfirreport.com/2026/08/24/bengalseo-part-1-anatomy-of-the-operation/