Recently unveiled by cybersecurity experts, a significant SEO poisoning campaign named BengalSEO has been focusing on deploying malware and executing tech support scams. This campaign, traced back to the Indian state of Rajasthan, has been active since at least 2015, involving two primary IT service firms: WeConnect Solutions LLC and Garage2Global. Though Garage2Global presents itself as a digital marketing service provider, investigations reveal its involvement in creating harmful web infrastructure supporting the BengalSEO scam network.
Techniques and Tools of BengalSEO
BengalSEO employs advanced SEO and web development skills to craft deceptive web pages, using various Black Hat SEO strategies. These lure pages are part of a comprehensive traffic distribution system designed to direct, monitor, and filter users to malware and tech support scams. The group has been utilizing a unique malware, MayaBot, since 2022, which facilitates system monitoring and cryptocurrency mining through XMRig. Their operations are financially driven, showcasing expertise in manipulating search engine results through a multitude of backlinks and sophisticated traffic systems.
The campaign uses a traffic distribution system (TDS) to guide victims through a series of redirector domains, eventually leading them to the malware or scam pages. Legitimate services like Matomo are employed for tracking and fingerprinting victims, further complicating the detection process. BengalSEO’s initial tactic involves SEO poisoning, pushing malicious pages to the top of Bing search results by imitating legitimate service portals for antivirus tools and other software.
Impact on Search Engines and Users
BengalSEO leverages aggressive user-generated content spam, backlink creation, and DOM manipulation to manipulate search engine algorithms and increase visibility. This approach involves flooding forums with links to lure pages and dynamically altering HTML structures to evade detection. Before victims reach the final payload page, they encounter security challenges designed to filter out automated scanners, ensuring the campaign’s longevity.
Once users land on the final page, they may be tricked into downloading a ZIP file containing a JavaScript dropper masquerading as legitimate software. In some instances, victims are directed to contact numbers under the pretext of resolving issues, further exemplifying the multifaceted nature of BengalSEO’s operations.
Infrastructure and Global Implications
The BengalSEO infrastructure heavily relies on reputable platforms like GitHub, pages.dev, and Cloudflare to host and manage lure pages, exploiting their trustworthiness to gain higher search rankings. Over 84 GitHub accounts linked to BengalSEO have been identified, utilized for developing and updating malicious content, and evading detection.
Additionally, similar campaigns by other groups, such as the Chinese-speaking Gambling Goblin, highlight a broader trend in global SEO manipulation. These campaigns target high-reputation domains, including government websites, to enhance search rankings and redirect traffic to phishing sites. The overarching goal is large-scale SEO manipulation, leveraging trusted domains to propagate malicious content and potentially deliver malware directly to users.
The findings underscore the critical need for robust cybersecurity measures and awareness to combat such sophisticated and far-reaching cyber threats. As BengalSEO continues to evolve, staying informed and vigilant remains crucial for both users and organizations worldwide.
