Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

BengalSEO: A Sophisticated SEO Poisoning Campaign Exploits Bing Search Results to Deliver Malicious Tech Support Scams and Phishing Attacks




A sophisticated search engine optimization (SEO) poisoning campaign, codenamed BengalSEO, has been discovered by cybersecurity researchers to poison Microsoft Bing search results, thereby delivering malicious tech support scams and phishing attacks. The campaign, which has been operating since at least 2015, is believed to be carried out by two IT service providers, namely WeConnect Solutions LLC (previously iConnect Soft Solutions LLC) and Garage2Global. The campaign's payload delivery domains are listed below, including ustechnio[.]com, tax.dll[.]lat, u320[.]my, reficon[.]pro, ñ[.]link, and pltechoo[.]pro. These domains serve no payloads in some instances, instead redirecting the victim to a contact page that instructs them to call a BengalSEO scam number to address an issue with their purported suspicious activity linked to their Bitdefender Central account. The campaign is a stark reminder of the sophistication and menace that cyber threats can pose, and it is essential that individuals and organizations remain vigilant and take proactive measures to protect themselves from such threats.

  • The BengalSEO poisoning campaign is a sophisticated search engine optimization (SEO) poisoning operation that has been operating since at least 2015.
  • The campaign, led by two IT service providers, WeConnect Solutions LLC and Garage2Global, uses malicious web infrastructure to manipulate search engine ranking algorithms.
  • The lure pages created by the campaign appear as legitimate technical support and service activation portals, but are actually used to deliver tech support scams and phishing attacks.
  • The campaign uses a traffic distribution system (TDS) to direct traffic to payloads and tech support scams, employing analytics services such as Matomo and Google Tag Manager.
  • The campaign's payload delivery domains include ustechnio[.]com, tax.dll[.]lat, u320[.]my, reficon[.]pro, ñ[.]link, and pltechoo[.]pro.
  • The campaign has been linked to multiple GitHub accounts and web page hosting platforms, which are used to aid in their SEO poisoning efforts.
  • The campaign's bulk of infrastructure was registered around August 2025 and later, with heightened activity continuing through late 2025 and early 2026.
  • A new campaign has been discovered targeting Brazilian government and educational institutions, attributed to a Chinese-speaking cybercrime cluster known as Gambling Goblin.



  • The world of cyber threats has witnessed a plethora of sophisticated attacks in recent times, each designed to exploit vulnerabilities and wreak havoc on unsuspecting victims. A recent case that has garnered significant attention is the BengalSEO poisoning campaign, which has been discovered by cybersecurity researchers to poison Microsoft Bing search results, thereby delivering malicious tech support scams and phishing attacks. In this article, we will delve into the details of this campaign and explore its implications on the cybersecurity landscape.

    At the heart of the BengalSEO poisoning campaign lies a sprawling search engine optimization (SEO) poisoning operation, which has been identified as a sophisticated threat actor. According to the DFIR Report, the campaign, codenamed BengalSEO, has been operating out of the Indian state of Rajasthan since at least 2015. The operation is believed to be carried out by two IT service providers, namely WeConnect Solutions LLC (previously iConnect Soft Solutions LLC) and Garage2Global.

    Garage2Global, one of the primary actors involved in the BengalSEO poisoning campaign, claims to be a website design, SEO, and digital marketing services provider. However, cybersecurity researchers have unearthed evidence indicating that the company develops malicious web infrastructure used in SEO poisoning campaigns as part of the BengalSEO scam cluster. This malicious infrastructure is utilized to create and promote lure pages with multiple black hat SEO techniques, thereby manipulating search engine ranking algorithms and artificially boosting the visibility of the lure pages on search engine results.

    The lure pages, designed to appear as legitimate technical support and service activation portals for streaming services, are promoted via SEO poisoning techniques to appear at the top of search results on Microsoft Bing. These decoy pages also claim to offer downloads for antivirus tools, gaming software, and taxation utilities, as well as activate credit, healthcare, and gift cards. One such example hijacks searches for "bitdefender central how to login" to serve a bogus link hosted on readthedocs[.]io, featuring a giant "Get Started" button that triggers the infection chain and routes unsuspecting users through a network of redirector domains to fingerprint the web browser and take them to appropriate final landing pages.

    The BengalSEO poisoning campaign employs a sophisticated traffic distribution system (TDS) to direct, track, and filter traffic to payloads and tech support scams. The TDS acts as a gating mechanism to lead victims to payload delivery domains through a redirector chain, while employing a legitimate privacy-first analytics service called Matomo for victim tracking and fingerprinting. Matomo is not the only analytics system used by BengalSEO; lure pages on hosting platforms such as github.io and pages.dev instead typically use analytics services such as Google Tag Manager.

    The campaign's payload delivery domains are listed below, including ustechnio[.]com, tax.dll[.]lat, u320[.]my, reficon[.]pro, ñ[.]link, and pltechoo[.]pro. These domains serve no payloads in some instances, instead redirecting the victim to a contact page that instructs them to call a BengalSEO scam number to address an issue with their purported suspicious activity linked to their Bitdefender Central account.

    The BengalSEO poisoning campaign has been observed using legitimate web page hosting platforms such as github.io, pages.dev, sites.google.com, and readthedocs.io to aid in their SEO poisoning efforts, likely weaponizing the trust and reputation of these services that factor into the search engine rankings. The campaign has also been linked to multiple BengalSEO-linked GitHub accounts, which were used for developing and hosting lure pages.

    These lure pages are constantly updated via commits to rotate redirector domains or temporarily replace them with legitimate URLs so as to avoid detection and replace domains that have been blocked or taken down. As many as 84 active BengalSEO GitHub accounts have been detected between Jan 2024 and March 2026. Further examination of the commit history made by these accounts has uncovered email addresses linking them to Garage2Global domains ("wc[.]ci").

    The bulk of the BengalSEO infrastructure is said to have been registered around August 2025 and later, with heightened activity continuing through late 2025 and early 2026. The domains have been registered across .my, .shop, and .info top-level domains (TLDs). Specifically, the domains were registered through Spaceship (47.6%) and Namecheap (28.6%). For hosting, the group heavily favored Cloudflare (81.1%) to proxy traffic, with Hostmaza serving as the origin host for 10.0% of domains.

    In related news, Check Point Research has shared details of a sustained campaign targeting Brazilian government and educational institutions since mid-2025 to turn their websites into a weapon for SEO manipulation. The activity has been attributed to a Chinese-speaking cybercrime cluster known as Gambling Goblin, which has ties to Earth Berberoka (aka GamblingPuppet), a threat actor known for singling out gambling websites across Asia since at least 2020.

    The group is "operating localized phishing networks in Portuguese, Vietnamese, Spanish, and English, while also maintaining infrastructure that generates new domains daily," the cybersecurity company told The Hacker News. "Together, these findings suggest this is not a regional experiment, but a model designed for global scale."

    The BengalSEO poisoning campaign is a stark reminder of the sophistication and menace that cyber threats can pose. As the threat landscape continues to evolve, it is essential that individuals and organizations remain vigilant and take proactive measures to protect themselves from such threats. In the coming days and weeks, it is crucial that we continue to monitor the situation and provide updates on the latest developments in this ongoing story.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/BengalSEO-A-Sophisticated-SEO-Poisoning-Campaign-Exploits-Bing-Search-Results-to-Deliver-Malicious-Tech-Support-Scams-and-Phishing-Attacks-ehn.shtml

  • https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html


  • Published: Tue Sep 8 05:17:32 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us