Find notable cyber news and cases, enriched with sources, timelines, and signals.

MayaBot malware activity in BengalSEO

Malware Activity
First reported
Last updated
Happening score
H score 10
1 unique sources, 1 articles

Summary

Hide ▲

The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, increasing both control and monetization of infected hosts. It is delivered through SEO-poisoned lure pages and ZIP archives that trigger a JavaScript dropper via wscript.exe. BengalSEO has leveraged the malware since 2022, showing the payload is a durable part of the infection chain.

Related Happenings

BengalSEO SEO poisoning campaign

Campaign
H score12 First: 08.09.2026 11:43 Last: 08.09.2026 11:43 Sources 1

How related: Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams.

About this happening: The BengalSEO operation now stands out as a long-running SEO poisoning campaign that funnels search users into MayaBot malware delivery and tech support scams. Dis...

ClickFix AmnesiaStealer distribution campaign targeting mac users

Campaign
H score22 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...

Latest development: 16.08.2026 18:07

Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.

XCSSET v40 macOS malware activity via compromised Xcode projects

Malware Activity
H score30 First: 04.08.2026 22:03 Last: 04.08.2026 22:03 Sources 1

About this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...

BoryptGrab infostealer variant delivered via fake GitHub repositories

Malware Activity
H score30 First: 14.07.2026 22:15 Last: 14.07.2026 22:15 Sources 1

About this happening: A BoryptGrab infostealer variant is being delivered through fake GitHub repositories, expanding a credential-theft operation that can drain browser, wallet, and messaging...

EtherRAT malicious MSI loader with Ethereum-based C2

Malware Activity
H score23 First: 30.04.2026 14:30 Last: 30.04.2026 14:30 Sources 1

About this happening: The EtherRAT malware is being delivered through malicious MSI installers and gives attackers persistent Windows access, increasing the risk of covert control inside en...

Timeline

  1. 08.09.2026 11:43 2 articles · 1d ago

    BengalSEO deploys MayaBot for command-and-control and XMRig mining

    Initial Disclosure

    Cybersecurity researchers disclosed that BengalSEO is a long-running SEO poisoning operation from Rajasthan, India, and that one of its payloads is MayaBot, a custom malware used since 2022 to provide command-and-control (C2), system monitoring, and XMRig cryptocurrency mining. The same operation uses lure pages, redirector chains, and a traffic distribution system to route victims into malware delivery or tech support scams.

    Show sources