BengalSEO: The Decade-Old Rajasthan Operation Poisoning Bing Results
Researchers say two Indian IT firms have quietly gamed search engines since 2015 to push malware and fake tech-support pop-ups.

Key points
- The DFIR Report disclosed the BengalSEO campaign in March 2026 after tracking it back to at least 2015.
- The operation runs out of Rajasthan, India, and is powered by two IT service providers trading as WeConnect.
- Poisoned search results push victims toward malware downloads and fake tech-support scams.
- The scheme mainly targets people using search engines like Bing to look up everyday queries.
- Ordinary users can protect themselves by ignoring urgent pop-ups that demand a phone call to "Microsoft support".
A decade-old scheme to trick search engines into serving up booby-trapped links has finally been dragged into daylight. Researchers at the DFIR Report published their findings in March 2026, giving the operation a name: BengalSEO.
The short version. Two IT firms in the Indian state of Rajasthan, both trading under the banner WeConnect, have spent years gaming search results so that innocent-looking queries lead to malware or fake tech-support pages. The group has been at it since 2015.
That is not a typo. Eleven years.
What is SEO poisoning, in plain English?
SEO poisoning is when criminals trick a search engine into ranking their malicious pages near the top of the results for popular searches. SEO stands for search engine optimisation, the ordinary business of getting your website to show up on Google or Bing. Poisoning is the criminal version.
Picture searching for a free template, a song lyric, or a driver for your printer. The top result looks legitimate. You click. Instead of the file you wanted, you land on a page that either downloads malicious software onto your computer or throws up a full-screen warning telling you your PC is infected and to call a number for "Microsoft support".
That call goes to a scam call centre, not Microsoft.
Who is behind BengalSEO?
The DFIR Report attributes the campaign to two IT service providers based in Rajasthan, both operating under the WeConnect name. According to the researchers, the outfit has been running the scheme since at least 2015, which makes it one of the longest-lived SEO poisoning operations documented in the wild.
The Hacker News, which covered the disclosure, notes that the group's two revenue streams work hand in hand: malware delivery for one set of customers, tech-support scam traffic for another. Both need the same thing, people clicking poisoned links.
What is actually being served to victims?
Two things, depending on the lure.
The first is malware, meaning software designed to steal information or give the attackers remote control of the machine. The second is a tech-support scam page: a browser window that locks up, plays an alarm sound, and tells the user to phone a number urgently. Anyone who calls is walked through handing over remote access or paying hundreds of dollars for fake "repairs".
| Detail | What the researchers found |
|---|---|
| Campaign name | BengalSEO |
| Disclosed by | The DFIR Report, March 2026 |
| Origin | Rajasthan, India |
| Active since | At least 2015 |
| Operators | Two IT firms trading as WeConnect |
| Payloads | Malware and tech-support scam pages |
Should ordinary internet users be worried?
A little caution goes a long way. SEO poisoning works because the malicious link is sitting inside search results you trust, not arriving in a suspicious email.
A few habits help. Look at the web address under a search result before clicking, especially if the domain is one you have never heard of. Never phone a number that pops up in your browser telling you your computer is infected: real operating system warnings do not include phone numbers. If a download starts on its own after a search, close the tab.
Businesses have a role too. Endpoint protection catches many of the payloads BengalSEO delivers, and browser isolation stops the pop-up scams from ever reaching the desktop.
Common questions
Is Bing the only search engine affected?
SEO poisoning campaigns typically target whichever search engine is easiest to manipulate for a given query. Bing has featured prominently in recent write-ups, but the underlying trick works against any search engine.
How do I know if I called a scam tech-support number?
If you were asked to install remote-access software, hand over a credit card, or buy gift cards to "pay for support", it was a scam. Disconnect the machine from the internet, run a full antivirus scan, and contact your bank if you paid anything.



