Skip to content

Security1 publisher3 min readPublished

DFIR Report puts eleven years of Bing SEO poisoning on two Rajasthan IT firms

MayaBot only shows up in 2022, seven years into the operation, and one branch of the funnel ends in a phone call to a scam call centre. That leaves the search referral and the redirector domains as the constants worth detecting.

The Watch · Security desk

What happened

  • The DFIR Report attributes BengalSEO, a search engine poisoning cluster it discovered in March 2026, to two Rajasthan IT service providers, WeConnect Solutions LLC and Garage2Global, operating since at least 2015.
  • Lure pages impersonating technical support and service activation portals are pushed to the top of Microsoft Bing results, including one that hijacks searches for "bitdefender central how to login".
  • Ranking comes from backlinks generated by forum and comment spam: a single Vizio setup decoy on a github.io subdomain carries 2,000 backlinks from 167 unique external domains.
  • Redirector domains in the traffic distribution system show a Cloudflare Turnstile or hCaptcha challenge to filter scanners and crawlers, and Matomo scripts fingerprint real browsers before the landing page.
  • The malware branch delivers MayaBot, used since 2022 for command-and-control, system monitoring and dropping an XMRig cryptocurrency miner.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Endpoint controls only see one of the two outcomes. Victims routed to the group's scam call centres never receive a file, so there is no process, hash or parent-child chain for EDR to alert on.
  • capability Challenge-gated redirectors plus DOM shuffling mean automated URL verdicts are formed on content the victim never sees, so blocklist feeds stay clean while the delivery path keeps working.
  • cost Because the decoys live on readthedocs.io and github.io, domain-level blocking costs the defender its own documentation and developer tooling, pushing detection down to path and referrer level.
  • precedent An operation with a decade of ranking assets and a company structure behind it sets the disruption target at registrars, hosts and search ranking, not at payload signatures that postdate it by seven years.

MayaBot entered the operation in 2022 [4]. DFIR Report dates the operation itself to at least 2015 [2]. That leaves roughly seven years of ranked lure pages and filtered traffic that predate the payload [18], and it means a MayaBot signature covers at most the last four years of an eleven-year business [17].

Two choices in the middle of the chain degrade the tooling that would otherwise flag these URLs. The redirector domains present a Cloudflare Turnstile or hCaptcha challenge before the payload page loads, which screens out scanners and crawlers [13]. DOM shuffling reorders page elements with embedded JavaScript so the same setup guide, deployed across hundreds of domains, reads as unique to a crawler [12]. The verdict a reputation feed returns for one of these links was formed on a challenge page. A user arriving from a Bing result in a real browser gets the other page [7].

Hosting removes the next-simplest control. The Bitdefender login decoy is served from readthedocs[.]io [9]; the Vizio setup lure sits on a github[.]io subdomain [11]. Neither is an attacker-registered domain you can null-route without cost [20].

What is left is on the wire and upstream of any executable: a search referral, a chain of redirector domains acting as the traffic distribution system's gate, and a Matomo script on both lure and landing pages beaconing browser fingerprints to stats.us3[.]org [6][14]. That beacon is the same on the malware branch and the scam branch.

The second branch is why endpoint coverage cannot be the whole answer. Victims steered off the technical support and activation lures are pushed to call the group's scam call centres [5][8], and those calls never trigger a file write or a process launch for EDR to see.

The corporate attribution is DFIR Report's and it is single-sourced. Garage2Global publicly presents itself as a website design, SEO and digital marketing provider; DFIR Report says it found evidence the company builds the malicious web infrastructure used by the BengalSEO cluster, alongside WeConnect Solutions LLC, formerly iConnect Soft Solutions LLC [2][3]. The material does not give a victim count or a revenue estimate, and neither firm has responded.

The one volume proxy in the writeup is modest. urlscan.io results for stats.us3[.]org stood at 1,112 at publication, down from 1,190 when the analysis was run [15]: 78 fewer, a decline of about 6.6 percent [16]. Set against 2,000 backlinks from 167 unique external domains pointing at a single Vizio decoy [11], that is an estate being maintained rather than dismantled.

The payload is the cheapest thing a black hat SEO shop that has held rankings for a decade owns, which is why payload detection does not disrupt it. The expensive assets are the backlink inventory, the cloaking, and the TDS [10][6]. Those live in search results and DNS, which is where the detection has to sit.

What to watch

  • Whether Microsoft demotes the ranked lure pages in Bing, and whether GitHub Pages and Read the Docs remove the decoys they host.
  • Whether urlscan visibility of stats.us3[.]org keeps sliding from 1,112 or the operators move fingerprint collection to a new domain.
  • Any response from WeConnect Solutions or Garage2Global to the DFIR Report's attribution, or action by Indian authorities.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories