```
A decade-long cybercrime operation has turned Bing search results into a distribution channel for both malware and fraudulent tech support schemes. Researchers at DFIR Report, as reported by The Hacker News, have exposed the campaign, dubbed BengalSEO, which has been active since at least 2015.
Tracing the activity back to the Indian state of Rajasthan, the investigation links the operation to two IT service providers: WeConnect and Webdelta. The campaign's core innovation lies in its dual-threat model, efficiently monetizing a single poisoned search result through two distinct malicious paths.
A Single Result, Two Criminal Endpoints
The BengalSEO campaign weaponizes user trust in search engine rankings. A manipulated link, appearing legitimate in search results, can lead to one of two outcomes depending on the victim's interaction:
- Malware Delivery: The result mimics a software download and delivers the MayaBot loader, initiating a malware infection chain.
- Tech Support Fraud: The same link directs victims to a convincing but fraudulent support portal, where they are pressured into paying for unnecessary and fictitious services.
This convergence of technical exploitation and social engineering within one operation maximizes its criminal revenue potential.
Strategic, Platform-Specific Poisoning
Unlike campaigns that broadly target multiple search engines, BengalSEO has exclusively focused on Bing. This deliberate strategy suggests the operators have exploited sustained weaknesses or lower defense thresholds within Bing's ranking ecosystem. Their "low-and-slow" tactic—making gradual, subtle manipulations—has allowed the campaign to evade detection for over eleven years, underscoring the challenges faced in identifying persistent, low-volume SEO poisoning.
Implications and Actionable Defenses
The longevity of BengalSEO reveals that users, and by extension the organizations they belong to, still place profound trust in search engine results. This trust is a vulnerability that is not always addressed in standard security awareness training.
Effective defense requires a layered approach:
- Technical Controls: Implement updated Endpoint Detection and Response (EDR) solutions to identify loaders like MayaBot. Use DNS filtering to block known malicious infrastructure tied to the campaign.
- Behavioral Changes: Train users to navigate directly to official vendor websites for software downloads or support, rather than trusting search results for these critical resources.
- Active Reporting: Foster a culture where users and IT teams promptly report suspicious search results to the search provider, contributing to the ecosystem's security.
The case highlights a critical gap: long-term, financially motivated campaigns persist by exploiting habitual user behavior. The operational details connecting WeConnect and Webdelta remain under investigation, but the broader lesson is clear—vigilance must extend to the very tools users rely on daily.
```
一項長達十年的網絡犯罪行動,已將必應搜尋結果變成惡意軟件及欺詐性技術支援計劃的分銷渠道。DFIR Report的研究人員(據The Hacker News報導)揭露了這場代號為BengalSEO的行動,該行動至少自2015年起一直活躍。
調查將其源頭追溯至印度拉賈斯坦邦,並將行動與兩家IT服務供應商:WeConnect及Webdelta聯繫起來。該行動的核心創新在於其雙重威脅模式,能透過兩條不同的惡意路徑,有效地從單一被投毒的搜尋結果中獲利。
單一結果 兩個犯罪終點
BengalSEO行動利用了用戶對搜尋引擎排名的信任。一個在搜尋結果中看似合法的操縱連結,可能會根據受害者的互動方式導致兩種結果:
- 惡意軟件投遞:該結果模擬軟件下載,並投遞MayaBot載入器,啟動惡意軟件感染鏈。
- 技術支援詐騙:同一連結將受害者引導至一個貌似可信但實為欺詐的支援門戶,他們在那裡被迫為不必要且虛構的服務付費。
此行動將技術利用與社會工程學結合,最大化了其犯罪收益潛力。
策略性、針對平台的投毒
與廣泛針對多個搜尋引擎的行動不同,BengalSEO專注於必應。這一刻意策略表明,操作者利用了必應排名生態系統中持續存在的弱點或較低的防禦閾值。他們的「低速緩進」策略——進行漸進且細微的操縱——使該行動得以避開偵測長達十一年以上,凸顯了識別持續性、低量SEO投毒所面臨的挑戰。
影響及可行防禦措施
BengalSEO的長壽命揭示了一點:用戶,以及他們所屬的組織,仍然對搜尋引擎結果抱有極大信任。這種信任是一個漏洞,並非在標準的安全意識培訓中總能解決。
有效的防禦需要多層次的方法:
- 技術控制:實施更新的端點偵測與回應(EDR)解決方案,以識別如MayaBot這類載入器。使用DNS過濾來封鎖與該行動相關的已知惡意基礎設施。
- 行為改變:訓練用戶直接導航至官方供應商網站進行軟件下載或尋求支援,而非依賴搜尋結果獲取這些關鍵資源。
- 積極通報:培養一種文化,鼓勵用戶及IT團隊及時將可疑的搜尋結果報告給搜尋引擎提供者,為整個生態系統的安全作出貢獻。
此案凸顯了一個關鍵缺口:長期、以金錢為動機的行動之所以持續存在,是因為它們利用了用戶的慣常行為。連接WeConnect與Webdelta的操作細節仍在調查中,但更廣泛的教訓顯而易見——警覺性必須延伸到用戶日常依賴的工具本身。
