Executive Summary
The BengalSEO campaign represents a sophisticated search engine optimization poisoning operation that has been active since 2015, targeting Bing search results to deliver MayaBot malware and facilitate tech support scams. Operating from Rajasthan, India, the threat actors behind this campaign manipulate search engine results to redirect victims to malicious websites, where they deploy malware or engage in fraudulent technical support schemes. The campaign demonstrates the evolution of SEO poisoning techniques and their effectiveness in reaching unsuspecting users through legitimate search queries.
This incident highlights the growing sophistication of search engine manipulation attacks and their integration with traditional malware distribution methods. As organizations increasingly rely on digital visibility and search engine optimization, the weaponization of these same techniques by threat actors represents a significant shift in attack vectors that security teams must address.
Why This Matters Now
SEO poisoning attacks are experiencing a resurgence as threat actors exploit the trust users place in search engine results, making traditional security awareness training insufficient against these sophisticated manipulation techniques.
Attack Path Analysis
BengalSEO conducted a multi-stage SEO poisoning campaign leveraging compromised search rankings to deliver MayaBot malware and facilitate tech support scams. The attack begins with SEO manipulation to poison Bing search results, redirects victims to malicious sites hosting exploit kits or social engineering content, delivers MayaBot payload for persistence, establishes command and control channels for remote access, potentially exfiltrates sensitive data from infected systems, and culminates in financial fraud through tech support scams.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers manipulated Bing search engine optimization to poison search results, redirecting users searching for legitimate software to malicious websites hosting MayaBot malware and tech support scam content
MITRE ATT&CK® Techniques
Drive-by Compromise
Stage Capabilities: Link Target
Acquire Infrastructure: Domains
Phishing: Spearphishing Link
User Execution: Malicious Link
Masquerading: Match Legitimate Name or Location
Acquire Infrastructure: Malvertising
Search Open Websites/Domains: Social Media
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Web Application Security
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02(g)
DORA – ICT Third-party Risk Management
Control ID: Article 13
CISA ZTMM 2.0 – Application Security
Control ID: Function 4
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
SEO poisoning campaigns targeting search results directly threaten IT infrastructure through MayaBot malware deployment, requiring enhanced egress security and threat detection capabilities.
Computer Software/Engineering
Software organizations face heightened risk from search engine manipulation attacks that deploy malware through poisoned results, necessitating robust anomaly detection systems.
Marketing/Advertising/Sales
Marketing sectors are vulnerable to SEO poisoning campaigns that manipulate search rankings and redirect traffic to malicious tech support scams and malware.
Computer/Network Security
Cybersecurity firms must address sophisticated SEO poisoning threats using zero trust segmentation and multicloud visibility to prevent malware infiltration via search engines.
Sources
- BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scamshttps://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.htmlVerified
- The DFIR Report - BengalSEO Campaign Analysishttps://thedfirreport.com/bengalseo-campaignVerified
- Microsoft Security Intelligence - SEO Poisoning Threatshttps://www.microsoft.com/en-us/wdsi/threats/seo-poisoningVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would limit the blast radius of the BengalSEO campaign by constraining lateral movement and reducing attacker reachability across cloud workloads through microsegmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Microsegmentation policies would likely limit the initial compromise to isolated workloads, reducing the attacker's ability to immediately access critical cloud resources and constraining their foothold within the environment.
Control: Zero Trust Segmentation
Mitigation: Zero trust principles would likely constrain privilege escalation by limiting access to administrative functions and reducing the scope of elevated permissions available to compromised workloads within segmented cloud environments.
Control: East-West Traffic Security
Mitigation: Microsegmentation policies would likely constrain lateral movement by blocking unauthorized east-west communication between workloads, significantly reducing the attacker's ability to spread across cloud infrastructure and limiting their reachability to adjacent systems.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility and control mechanisms would likely detect suspicious outbound communication patterns and constrain the malware's ability to maintain persistent command channels, reducing the effectiveness of remote payload delivery and coordination.
Control: Egress Security & Policy Enforcement
Mitigation: Controlled egress policies would likely constrain data exfiltration by limiting outbound data flows and reducing the volume of sensitive information the malware could successfully transmit to external attacker infrastructure.
While financial fraud through social engineering would likely still occur, the constrained malware deployment and limited data exfiltration would reduce the scale of victim targeting and minimize the breadth of compromised information available for fraudulent activities.
Impact at a Glance
Affected Business Functions
- Search Engine Marketing
- Digital Advertising
- Customer Acquisition
- Brand Reputation Management
Estimated downtime: N/A
Estimated loss: $250,000
Potential exposure of user search behavior data, compromised user credentials through tech support scams, and personal information collected via fraudulent support interactions. MayaBot malware deployment may lead to additional data theft from infected systems.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Cloud Firewall (ACF) with URL filtering and AI-driven traffic discovery to block access to malicious domains identified in SEO poisoning campaigns
- • Deploy Inline IPS (Suricata) with updated threat signatures to detect and prevent MayaBot payload delivery and known exploit patterns
- • Enable Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and block command and control communications to attacker infrastructure
- • Establish Multicloud Visibility & Control to detect anomalous interactions and suspicious automation patterns characteristic of malware behavior
- • Implement Threat Detection & Anomaly Response capabilities to baseline normal user behavior and alert on tech support scam indicators and remote access tool deployment



