BengalSEO Tricks Bing Users Into Malware & Scam Calls

The Hacker News · High sophistication
Last updated September 8, 2026

Researchers uncovered a long-running “SEO poisoning” operation that manipulates Bing search results to push people onto fake support and activation pages. Victims are steered through a chain of redirects to either download a malware-laced ZIP (MayaBot) or be pressured into calling a fake tech-support call center. The campaign relies on trusted hosting platforms and heavy backlink spam to make the fake pages look legitimate and rank highly.

Key findings

  • Attackers manipulated Microsoft Bing results (SEO poisoning) to drive victims to malicious “lure pages.”
  • Lure pages impersonated legitimate support/activation portals (e.g., streaming services, antivirus, cards) to get clicks and trust.
  • Victims were funneled through a traffic distribution system (TDS) with fingerprinting/tracking and bot filtering (e.g., Turnstile/hCaptcha).
  • Some victims were pushed to download a ZIP containing a JavaScript dropper that runs via wscript.exe to install MayaBot; others were pushed into calling scam call centers.
  • The campaign leveraged reputable hosting platforms (e.g., GitHub Pages, ReadTheDocs) and large-scale backlink spam to boost ranking and credibility.

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, IT, Helpdesk.
  • Affected industries: Software and online services, Consumer tech support and IT services, Finance (credit card-related lures), Healthcare (health card-related lures), Government/tax services (tax utility-related lures).
  • Attack channels: website, vishing.
  • Impersonated: Bitdefender Central support/login, Bitdefender account/security support.

Awareness takeaways

  • Treat top search results as untrusted, verify you are on the real vendor domain before clicking buttons or downloading anything.
  • Do not download ‘fix tools’ or ‘support software’ from unknown pages; use official sources and internal IT-approved download methods.
  • Be wary of “security alert” pages that tell you to call a phone number, use known, official support channels instead.
  • Trusted hosting platforms can be abused; a familiar domain (e.g., GitHub Pages/ReadTheDocs) does not guarantee legitimacy.

Red flags to watch for

  • Top search result leads to a non-official hosting domain (e.g., documentation/hosting platform rather than the real vendor site)
  • Overly generic, oversized “Get Started” style button with unclear destination
  • Unexpected download flow tied to a “login/help” search
  • Security alert that pushes you to call a number found on a web page (not from an official app or known contact channel)
  • Urgent “suspicious activity” claim with no verifiable details
  • Support interaction begins from a search-result page rather than an official vendor site
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You search Bing for “bitdefender central how to login”… click the top result… and that’s exactly how BengalSEO gets you. Their SEO poisoning pushes you to a fake Bitdefender Central page on readthedocs.io with a giant “Get Started” button. Click it, and you’re funneled through redirects to a “Download for Windows” ZIP that secretly drops MayaBot. Same trick, different ending: sometimes the redirects land on a “Suspicious activity linked to your Bitdefender Central account” page that flashes a phone number and tells you to call support, that’s a BengalSEO scam call center. Aha moment: the top Bing result and a familiar host like readthedocs.io don’t prove it’s legit. One move: before you click any big button or call any number, check the domain in the address bar, if it’s not the real vendor site, back out.

Similar attacks

BengalSEO: Search Lures to Malware & Scam Calls

BengalSEO: Search Lures to Malware & Scam Calls

Investigators described a real, long-running SEO poisoning operation (“BengalSEO”) that manipulates search results to push victims to fake support and activation pages. The pages impersonate well-known consumer brands, then route visitors through redirects and CAPTCHA checks to either download…

September 1, 2026
Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Fake Claude & Perplexity Lures Push Malware

Fake Claude & Perplexity Lures Push Malware

Sophos reports real incidents where attackers impersonated well-known AI brands (especially Claude) to trick people into installing malware. The lures included polished fake installer pages that instruct victims to copy/paste commands, and browser extensions that look legitimate via high ratings…

August 21, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Browser Trust Scams: Fake Updates, BitB, ClickFix

Browser Trust Scams: Fake Updates, BitB, ClickFix

Cofense reports multiple real-world campaigns where attackers don’t hack the browser, they trick employees by copying normal browser experiences like login pop-ups, software update prompts, and “verification” checks. The goal is to get users to enter credentials, approve attacker sessions, or run…

August 26, 2026