BengalSEO Scam Operation Exposed After 10 Years of Search Fraud
⚠️ Threat Level: High – An active scam ring is pushing fake tech support pages to the top of Google and Bing results and deploying custom malware to real users. If you have recently searched for antivirus, tax software, or streaming support, you may have been targeted.
Security researchers at The DFIR Report have exposed a decade-long BengalSEO scam operation linked to two companies in Kota, Rajasthan, India. The group manipulates search engine rankings to push fake support pages above legitimate results, filters victims through a custom tracking system, and either installs malware on their device or routes them to a fraudulent call center.
The investigation, published on 24 August 2026, is the first part of a multi-part series.
WeConnect Solutions and Garage2Global: The Two Indian Companies Running BengalSEO
Researchers attributed the operation with high confidence to two named companies. The first is WeConnect Solutions LLC (formerly iConnect Soft Solutions LLC), a tech support call center based in Kota, Rajasthan. The second is Garage2Global, a company that markets itself publicly as a legitimate SEO and web development agency and operates from the same office building.
The DFIR Report found GitHub accounts using Garage2Global email addresses to build and host fake brand support pages. “Our team attributes this operation, with high confidence, to a group of core individuals and IT service providers operating out of Rajasthan, India,” researchers wrote. The BengalSEO scam operation has been running since at least 2015.
Fake Bitdefender Pages, Bot Filters, and Scam Calls: How BengalSEO Traps Victims
BengalSEO uses SEO poisoning, meaning they game search engine rankings to push their fake pages above legitimate results. Searches for Bitdefender support, TurboTax help, Hulu activation, or UnitedHealthcare card activation can land a user on one of their fake pages.
Their lure pages are deliberately hosted on trusted platforms including GitHub Pages, Google Sites, and Cloudflare Pages. This trust boost from reputable domains, combined with black hat SEO techniques including backlink spam and keyword stuffing, helps their pages rank at or near the top of results.
When a victim clicks the support button on a fake page, they are passed through BengalSEO’s Traffic Distribution System (TDS), a custom routing engine that:
- Presents a CAPTCHA challenge to screen out security scanners and bots.
- Fingerprints the browser, collecting IP address, screen size, browser type, and mouse movement patterns.
- Routes confirmed human visitors to the malicious page and sends automated scanners to a harmless decoy.
MayaBot: The Custom Malware BengalSEO Built to Disguise Itself as Your Software Download
Victims who clear the TDS filter are taken to a fake download page. They are told to install software tied to the brand they searched for. The download is a ZIP file containing MayaBot, a custom malware dropper the DFIR Report named after the Sanskrit word for “illusion.”
Inside the ZIP is a JavaScript file disguised as an EXE. Once run, it executes using a built-in Windows script runner called wscript.exe. MayaBot has been in active deployment since 2022 and is designed to enable further scam operations on infected machines.
Where no malware is served, victims are instead redirected to a BengalSEO call center number. An operator then attempts to defraud them directly over the phone.
84 GitHub Accounts and 1,190 Flagged Pages: The Full Scope of the Infrastructure
The investigation uncovered numbers that show how large this operation has become:
- 84 active GitHub accounts used to build and rotate lure pages between January 2024 and March 2026.
- 1,190 pages detected loading BengalSEO’s shared Matomo analytics tracker.
- 411 subdomains tied to a single domain cluster used as traffic redirectors.
- A major registration surge from mid-2025 onward, with hundreds of bulk domain purchases across
.my,.shop, and.infoextensions.
US Consumers Searching for Antivirus, Tax, and Streaming Support Are the Primary Targets
BengalSEO focuses on US consumers searching for product support. Their fake pages impersonate well-known brands across five categories:
- Antivirus software (Bitdefender, Norton, McAfee)
- Tax software (TurboTax, H&R Block)
- Streaming services (Hulu, Plex, Paramount+)
- Gaming software downloads
- Healthcare and card activation (UnitedHealthcare, Capital One, Kohl’s)
Researchers noted a surge in healthcare-themed campaigns in late 2025 that appeared to coincide with the passage of the US One Big Beautiful Bill Act, suggesting BengalSEO monitors US policy events to refine their targeting strategy.
How to Spot a Fake Tech Support Page and Protect Yourself from MayaBot
If you use search engines to find software or service support, take these steps:
- Never call a number found on a page you reached through a search result. Go directly to the brand’s official website by typing the URL yourself.
- If you downloaded a ZIP file from a support page in the past year, scan your device immediately with a trusted antivirus tool.
- Check the web address carefully before clicking anything. Fake pages are rarely hosted on the brand’s actual domain. GitHub or Cloudflare Pages URLs for a major brand’s support site are a red flag.
- Do not run files from any ZIP you did not specifically request from a verified, official source.
- Report fake pages to Google at
safebrowsing.google.com/safebrowsing/report_phish/.
DFIR Report Part Two Is Coming and the Full IOC List Is Already Live
The DFIR Report confirmed this is the first in a multi-part series. Further findings on BengalSEO’s wider infrastructure, malware behaviour, and linked individuals are expected in the coming weeks.
A full indicator list covering campaigns from 2023 to 2026 is already public on GitHub. Security teams can use it immediately to hunt for BengalSEO activity across their environments. Subscribe to the DFIR Report to be notified when Part 2 publishes.
No Comment! Be the first one.