home.social

#seopoisoning — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #seopoisoning, aggregated by home.social.

  1. Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

    A massive cybercrime campaign tracked as CL-CRI-1171 has operated undetected for at least two years, utilizing a pay-per-install marketplace to distribute multiple malware families. The operation targeted primarily young gamers through YouTube channels with hundreds of thousands of followers, while simultaneously using SEO poisoning to compromise corporate endpoints including critical infrastructure and government entities. The campaign employed OfferLoader, a custom loader capable of delivering unique payload combinations through sophisticated gating mechanisms. Three distinct malware families were identified: Insomnia RAT, a cross-platform backdoor targeting Windows and macOS; ARKTunnel, a WebSocket tunneling tool hidden via steganography; and Docro Hijacker, a Chrome browser hijacker. Over 10,000 distinct loader samples were discovered, indicating a much larger deployment campaign affecting numerous organizations globally.

    Pulse ID: 6aa13e05864a561a7db38073
    Pulse Link: otx.alienvault.com/pulse/6aa13
    Pulse Author: AlienVault
    Created: 2026-09-09 11:07:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Endpoint #Government #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #SEOPoisoning #SMS #Steganography #Windows #YouTube #bot #AlienVault

  2. BengalSEO Campaign Exploits Bing Search Results

    Meet BengalSEO, a notorious group that's been secretly manipulating Bing search results with sneaky Black Hat SEO tactics since at least 2015, luring victims into malware and tech-support scams. They're masters of creating fake support pages that look legit, but actually serve as traps.

    osintsights.com/bengalseo-camp

    #Bengalseo #BlackHatSeo #SeoPoisoning #MalwareOperations #TechsupportScams

  3. BengalSEO Part 1: Anatomy of the Operation

    In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...

    Pulse ID: 6a9d1727de29faddfa1c2a91
    Pulse Link: otx.alienvault.com/pulse/6a9d1
    Pulse Author: AlienVault
    Created: 2026-09-06 07:32:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault

  4. BengalSEO Part 1: Anatomy of the Operation

    In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...

    Pulse ID: 6a9d1727de29faddfa1c2a91
    Pulse Link: otx.alienvault.com/pulse/6a9d1
    Pulse Author: AlienVault
    Created: 2026-09-06 07:32:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault

  5. BengalSEO Part 1: Anatomy of the Operation

    In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...

    Pulse ID: 6a9d1727de29faddfa1c2a91
    Pulse Link: otx.alienvault.com/pulse/6a9d1
    Pulse Author: AlienVault
    Created: 2026-09-06 07:32:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault

  6. BengalSEO Part 1: Anatomy of the Operation

    In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...

    Pulse ID: 6a9d1727de29faddfa1c2a91
    Pulse Link: otx.alienvault.com/pulse/6a9d1
    Pulse Author: AlienVault
    Created: 2026-09-06 07:32:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault

  7. BengalSEO Part 1: Anatomy of the Operation

    In March 2026, a sophisticated SEO poisoning campaign was identified leading to malware distribution and tech support scams. Operating since at least 2015, this operation is attributed to individuals and IT service providers in Rajasthan, India, collectively tracked as BengalSEO. Two primary entities were identified: WeConnect Solutions LLC operates tech support call centers, while Garage2Global develops malicious web infrastructure. The group leverages extensive black hat SEO techniques including backlink generation, DOM injection, and keyword stuffing to promote lure pages mimicking legitimate technical support portals. A custom Traffic Distribution System routes victims through rotating redirector domains, utilizing Matomo analytics for tracking and fingerprinting. The operation deploys custom malware named MayaBot to further enable scam activities. Infrastructure analysis revealed hundreds of domains registered primarily through Spaceship and Namecheap, hosted via Cloudflare and Hostmaza, with GitHub e...

    Pulse ID: 6a9d1727de29faddfa1c2a91
    Pulse Link: otx.alienvault.com/pulse/6a9d1
    Pulse Author: AlienVault
    Created: 2026-09-06 07:32:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #GitHub #ICS #India #InfoSec #Malware #Mimic #NATO #Namecheap #OTX #OpenThreatExchange #RAT #SEOPoisoning #Word #bot #AlienVault