BengalSEO Part 1: Anatomy of the Operation
The DFIR Report details a long-running SEO poisoning and tech support scam operation dubbed BengalSEO, attributed to a group operating out of Rajasthan, India through companies WeConnect Solutions and Garage2Global. The operation uses black hat SEO techniques (DOM injection, DOM shuffling, backlink spam, keyword stuffing) to promote lure pages mimicking support portals, funnels victims through a custom Traffic Distribution System with CAPTCHA filtering and Matomo-based fingerprinting, and delivers a custom JavaScript-based malware called MayaBot or redirects victims to scam call centers. The report covers infrastructure details including GitHub-hosted lure pages, hosting providers (Hostmaza), registrars (Spaceship), domain registration timelines, and pivoting techniques using Validin, VirusTotal, and urlscan.io to map hundreds of associated domains.
