BengalSEO Part 1: Anatomy of the Operation

DFIR Report identified BengalSEO, a Rajasthan-based scam operation that has used SEO poisoning, malicious lure pages, and a traffic distribution system to deliver the MayaBot malware and drive tech support fraud since at least 2015. The campaign relies on companies such as WeConnect Solutions LLC and Garage2Global, along with infrastructure spanning GitHub, Hostmaza, Cloudflare, Matomo, and numerous redirector and payload domains. #BengalSEO #MayaBot #WeConnectSolutionsLLC #Garage2Global #Hostmaza #Cloudflare #Matomo

Keypoints

  • BengalSEO is a long-running scam operation based in Rajasthan, India, attributed with high confidence to core individuals and IT service providers.
  • The group uses SEO poisoning and fake support or activation pages to push victims into either downloading malware or calling scam phone numbers.
  • WeConnect Solutions LLC and Garage2Global were identified as key business entities driving the operation, with shared ownership and infrastructure links.
  • BengalSEO built a custom malware loader/droplet named MayaBot, which has been used since 2022 to support scam activity.
  • A custom traffic distribution system routes visitors through rotating redirector domains, captcha checks, and browser fingerprinting before serving payloads or benign decoys.
  • The campaign leverages Matomo, Google Tag Manager, GitHub, and multiple hosting/registration providers to track visitors, host lure pages, and rotate infrastructure.
  • Research uncovered hundreds of related domains, SSL certificates, subdomains, and GitHub accounts tied to BengalSEO activity from 2023 through 2026.

MITRE Techniques

  • [T1036 ] Masquerading – The group disguises fake support pages, fake software downloads, and a JavaScript dropper as legitimate tools or files [ā€˜The lure pages mimic legitimate technical support and service activation portals’ / ā€˜Inside the ZIP file is a MayaBot JavaScript dropper masquerading as an exe file.’]
  • [T1566 ] Phishing – Victims are lured through deceptive support and activation pages that push them toward scams or malicious downloads [ā€˜mimic legitimate technical support and service activation portals’ / ā€˜trick victims into calling their scam call centers’]
  • [T1583.001 ] Acquire Infrastructure: Domains – BengalSEO registers and uses large numbers of domains for redirectors, lure pages, landing pages, and payload hosting [ā€˜Between 2023 and 2026, our team identified hundreds of domains and SSL certificates tied to BengalSEO.’]
  • [T1583.006 ] Acquire Infrastructure: Web Services – The operation uses GitHub, pages.dev, github.io, readthedocs.io, and other web hosting services to publish lure infrastructure [ā€˜BengalSEO utilizes page hosting platforms such as github.io, pages.dev. sites.google.com, and readthedocs.io.’]
  • [T1587.001 ] Develop Capabilities: Malware – The group built a custom malware strain, MayaBot, to support scam operations [ā€˜This includes deploying a custom malware strain our team has named MayaBot’]
  • [T1027 ] Obfuscated Files or Information – JavaScript, URLs, and payloads are obfuscated or encoded to hide their purpose and evade detection [ā€˜obfuscated ASCII character codes’ / ā€˜Base62 or base64 encoding’ / ā€˜Obfuscated MayaBot JavaScript dropper source’]
  • [T1071.001 ] Application Layer Protocol: Web Protocols – The campaign uses HTTP GET/POST, redirects, and web-based tracking to move victims through the delivery chain [ā€˜the redirector server issues an HTTP 302 redirect’ / ā€˜HTTP POST request to stats.us3[.]org/matomo.php’]
  • [T1090.003 ] Proxy: Multi-hop Proxy – Traffic is routed through rotating redirector domains to hide final destinations and distribute victims [ā€˜using a rotating network of redirector domains to route victims from lure pages to final landing pages’]
  • [T1497.001 ] Virtualization/Sandbox Evasion: System Checks – Captcha challenges and browser fingerprinting are used to filter out automated analysis and bots [ā€˜deploy a Cloudflare Turnstile or hCaptcha challenge to filter out automated crawlers, scanners, and bots’]
  • [T1057 ] Process Discovery – The payload execution path references wscript.exe, which executes the JavaScript dropper [ā€˜the JavaScript executes via wscript.exe and initiates the Mayabot infection’]
  • [T1204.002 ] User Execution: Malicious File – Victims are instructed to download and open a ZIP archive containing the malicious dropper [ā€˜the victim begins downloading a ZIP archive’ / ā€˜prompted with instructions to open and execute the contents of the downloaded ZIP file’]
  • [T1105 ] Ingress Tool Transfer – The lure-to-payload chain delivers malicious content from hosted landing pages to victim systems [ā€˜deliver the MayaBot malware’ / ā€˜serving payloads to final landing pages’]
  • [T1568.002 ] Dynamic Resolution: Domain Generation Algorithms – While not a classic DGA, the operation heavily rotates numbered and patterned domains across many TLDs to continually refresh infrastructure [ā€˜bulk domains using numbered us, act, and pc naming conventions across .my, .shop, and .info TLDs’]

Indicators of Compromise

  • [Domains ] redirector and tracking infrastructure – ts.remdos[.]com, tx.newredir[.]com, and 12 more redirector domains
  • [Domains ] analytics and telemetry – stats.us3[.]org, wapp[.]live, and other related subdomain infrastructure
  • [Domains ] payload delivery and landing pages – ustechnio[.]com, tax.dll[.]lat, and 4 more payload domains
  • [Domains ] business and supporting sites tied to BengalSEO – wc[.]ci, garage2global[.]com, and other associated domains
  • [IP Addresses ] hosting and infrastructure resolution – 5.101.140[.]80, plus other infrastructure-linked IPs referenced via DNS pivots
  • [File/Script Names ] tracking and payload artifacts – matomo.js, bootstrap-table.min.css, and the MayaBot JavaScript dropper
  • [Hosting/Service Platforms ] infrastructure used for lure pages and analysis – github.io, pages.dev, readthedocs.io, and other hosting services
  • [SSL/TLS Certificates / Subdomains ] certificate and subdomain pivots – 411 subdomains for wapp[.]live, 80 for aol[.]cx, and 43 for iconnectpc[.]com


Read more: https://thedfirreport.com/2026/08/24/bengalseo-part-1-anatomy-of-the-operation/