A sophisticated cyberattack has been uncovered, where a malicious actor manipulated Bing search results to deliver payloads of two notorious malware variants, MayaBot and Tech Support Scams. The campaign, dubbed BengalSEO, exploited vulnerabilities in Microsoft’s search engine optimization (SEO) tools, allowing attackers to inject poisoned links into seemingly legitimate search results.
At the heart of this scheme lies a clever manipulation of how search engines rank websites. By creating fake, high-quality content that mimics real websites, attackers were able to game Bing’s algorithms and boost their own website’s visibility in search results. This gave them a prime opportunity to inject malicious links into unsuspecting users’ browsers. When clicked, these links would download and install the MayaBot malware or prompt users to engage with Tech Support Scams.
MayaBot is a notorious information stealer that can extract sensitive data from infected devices, including login credentials, credit card numbers, and personal identifiable information (PII). Tech Support Scams, on the other hand, are social engineering tactics designed to deceive users into divulging their login credentials or paying for fake technical support services. Both types of malware have been linked to significant financial losses and identity theft.
This campaign’s impact is further exacerbated by its reliance on a seemingly innocuous service: Microsoft’s SEO tools. These tools were designed to help website owners optimize their content for search engines, but in the wrong hands, they become a powerful tool for manipulating online traffic. The ease with which attackers exploited these vulnerabilities raises concerns about the security of Bing’s algorithm and the potential for similar manipulations.
The BengalSEO campaign serves as a stark reminder that cybersecurity threats can emerge from even the most unexpected places. It highlights the importance of vigilance in search engine optimization, as well as the need for robust defenses against malware and social engineering tactics. As users, it is essential to remain cautious when interacting with online content, especially if it seems too good (or suspicious) to be true.
In light of this discovery, we urge all users to exercise increased caution when browsing search results and engaging with online services that offer technical support or promise easy money. Always verify the authenticity of websites and links before clicking on them, and consider investing in reputable antivirus software and a robust firewall configuration to protect against malware attacks.
Source: The Hacker News — 2026-09-08