A sprawling SEO poisoning campaign operating since at least 2015 has flooded Bing search results with malicious links, routing victims toward malware known as MayaBot and predatory tech support scams. The DFIR Report identified the operation in March 2026 and labeled it BengalSEO, tracing its command infrastructure and operators to Rajasthan, India, where two IT service providers named WeConnect have orchestrated the scheme.

BengalSEO exploits legitimate SEO techniques to artificially elevate malicious websites in Bing's search rankings. When users search for common terms, poisoned results direct them to landing pages hosting MayaBot malware or fake tech support portals. The scammers impersonate Microsoft support staff, claiming users have system infections or security breaches. Victims who interact with these fake support pages download MayaBot, which establishes persistence on their machines and enables remote access for attackers.

MayaBot represents a capable infostealer and remote access trojan. Once installed, the malware harvests browser credentials, banking information, and cryptocurrency wallets. It retrieves clipboard contents, captures keystrokes, and exfiltrates files. The malware also accepts remote commands, allowing operators to deploy additional payloads or pivot laterally into corporate networks when business systems become compromised.

The tech support scam component targets both individuals and small businesses. Victims receive pop-up warnings claiming their system requires immediate attention. Fake support phone numbers route callers to BengalSEO operatives, who charge hundreds or thousands of dollars for unnecessary "repairs" while installing MayaBot during remote sessions. Some victims have reported charges exceeding fifteen hundred dollars for fake services.

Researchers identified WeConnect as a central player in the operation. The company operates legitimate IT service contracts in India but runs the BengalSEO campaign as a parallel criminal enterprise. Infrastructure analysis revealed shared hosting, payment processing accounts, and email addresses linking multiple malicious domains and landing pages directly to WeConnect employees.

The campaign targets English-speaking users globally, though Indian and Pakistani victims represent a significant portion of infected systems. Bing's user base in emerging markets makes it a preferred vector compared to Google, which implements stricter link quality controls. Researchers observed that BengalSEO campaigns spike during specific times, suggesting coordinated operational tempo rather than passive automation.

Bing has reportedly removed thousands of poisoned links following DFIR Report disclosure. However, operators continuously regenerate compromised domains and adjust SEO tactics to evade detection. The campaign demonstrates how established SEO poisoning techniques remain effective against major search engines when combined with social engineering and malware distribution.

Organizations and individuals should employ several defensive measures. Use reputable antivirus software and keep systems fully patched. Avoid clicking links from search results offering unexpected support services or system warnings. Verify technical support through official vendor websites and phone numbers rather than pop-up notifications. Enable multifactor authentication on banking and cryptocurrency accounts to contain credential theft damage.

The BengalSEO operation illustrates how criminal enterprises maintain profitability by combining low-cost malware delivery with high-pressure social engineering. As long as a fraction of millions of search users fall victim, operators sustain revenue to expand their infrastructure. The campaign will likely persist despite targeted takedowns, adapting delivery methods and search engine targets as defenders respond.