A sophisticated cyber campaign has been uncovered, targeting Bing search engine users with poisoned results designed to deliver malicious payloads and phishing scams. BengalSEO, a notorious group behind previous attacks on Google’s AdWords platform, is allegedly responsible for this latest scheme, dubbed “MayaBot.” The attack vector leverages Bing’s proprietary search algorithm to inject malware-laced ads into seemingly legitimate search results.
The victims of this campaign are likely unaware that their innocuous searches have been hijacked by malicious actors. BengalSEO’s tactics involve exploiting vulnerabilities in cross-domain privilege escalation (CPE) protocols, essentially allowing them to “jump” between websites and inject malware into unsuspecting users’ browsers. This CDE flaw allows attackers to manipulate the search results displayed on Bing, injecting links that appear as normal but are actually designed to phish or scam users.
One of the primary objectives behind this campaign appears to be delivering MayaBot, a remote access Trojan (RAT) capable of exfiltrating sensitive data from compromised devices. This malware is designed to be stealthy and evasive, making it difficult for detection by traditional security software. By getting victims to click on malicious links, attackers can gain unauthorized access to sensitive information such as login credentials, financial details, or even personal identifiable information (PII).
The Tech Support Scam aspect of this campaign involves directing victims to fake tech support websites that promise to fix supposed issues with their devices or operating systems. These sites are often masquerading as legitimate Microsoft or Apple support pages and will try to extract sensitive data from the victim’s device by convincing them to download malicious software or pay for unnecessary repairs.
The MayaBot campaign is a stark reminder of the ongoing cat-and-mouse game between attackers and defenders in cyberspace. With BengalSEO employing increasingly sophisticated tactics, it’s becoming more challenging for users to remain safe online. As cybersecurity professionals and experts continue to work on improving detection methods and developing new countermeasures, individuals must also take proactive steps to protect themselves.
To stay ahead of these attacks, users should be cautious when clicking on links from search results and always verify the authenticity of websites before providing sensitive information or downloading software. Regularly updating operating systems, browsers, and security software is essential for mitigating risks associated with such campaigns.
Source: The Hacker News — 2026-09-08