BengalSEO Scam: How Bing Search Results Get Poisoned
Michael Miller ·
Listen to this article~5 min
A decade-long SEO poisoning campaign called BengalSEO is hijacking Bing search results to spread malware and tech support scams. Here's what you need to know.
### The Quiet Campaign That's Been Running Since 2015
Imagine typing a normal question into Bing, clicking the first result, and landing on a page that looks fine—until a fake popup tells you your computer is infected. That's the trick behind a campaign cybersecurity researchers are calling BengalSEO. It's been quietly poisoning search results for years, and most people have never heard of it.
The DFIR Report uncovered the operation in March 2026. It's been running out of Rajasthan, India, since at least 2015, tied to two IT service providers called WeConnect. The goal? Push victims toward malware like MayaBot and tech support scams that demand payment to "fix" problems that don't exist.
### What SEO Poisoning Actually Means
SEO poisoning is simple in concept. Attackers stuff fake pages with popular search terms, then wait for search engines to rank them. When you search for something common—like "how to speed up my PC"—their page shows up near the top. You click, you land, and the trap springs.
- **Fake tech support pages** that show alarming popups and a phone number to call
- **Malicious downloads** hiding under the guise of free tools or updates
- **MayaBot malware** that quietly installs itself and steals data
- **Fake error messages** designed to panic you into paying for "support"
What makes BengalSEO stand out is how long it's lasted. Most campaigns burn out in weeks. This one has been going for over a decade.
### Why Bing and Why Now
Bing doesn't get the same scrutiny as Google, which makes it a softer target. Attackers know this. They also know that many people trust search results without thinking twice. If a page looks legitimate and ranks well, most users assume it's safe.
The DFIR Report notes that the campaign is driven by two IT service providers, which means this isn't just a few hackers in a basement. It's organized. These groups have infrastructure, funding, and a business model built on scaring people into paying.
> "The scariest part isn't the malware itself—it's how normal the whole thing looks. You'd never know you were being targeted until it's too late."
### How to Protect Yourself
You don't need to be a security expert to stay safe. A few habits go a long way.
- **Never call a number from a popup.** Real companies don't work that way.
- **Check the URL before you click.** If something feels off, it probably is.
- **Keep your browser updated.** Old versions are easier to exploit.
- **Use a reputable antidetect browser** if you manage multiple accounts or do sensitive work online. It adds a layer of separation between you and shady sites.
- **Run a trusted antivirus.** It won't catch everything, but it catches a lot.
### What This Means for Everyday Users
BengalSEO is a reminder that search results aren't automatically safe. They're just a list of pages a search engine thinks might help you. Sometimes they're wrong. Sometimes they're paid for. And sometimes, they're designed to hurt you.
The campaign is still active as of early 2026. Researchers are tracking it, but takedowns take time. In the meantime, the best defense is awareness. If a page feels pushy, urgent, or too good to be true, close the tab. Your instincts are usually right.
### The Bigger Picture
Scams like this work because they exploit trust. We trust search engines to show us good results. We trust websites to be honest. We trust popups to be real warnings. Attackers know this, and they build their entire operation around that trust.
Staying safe online isn't about paranoia. It's about paying attention. A little skepticism goes a long way—especially when someone's trying to get your money or your data.