Find notable cyber news and cases, enriched with sources, timelines, and signals.

MayaBot malware activity in BengalSEO

Malware Activity
First reported
Last updated
Happening score
H score 10
1 unique sources, 1 articles

Summary

Hide ▲

The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, increasing both control and monetization of infected hosts. It is delivered through SEO-poisoned lure pages and ZIP archives that trigger a JavaScript dropper via wscript.exe. BengalSEO has leveraged the malware since 2022, showing the payload is a durable part of the infection chain.

Related Happenings

Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories

Malware Activity
H score26 First: 18.09.2026 18:19 Last: 18.09.2026 18:19 Sources 1

About this happening: Rapuncel is an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to impersonate software brands, including LastPass, and lure people search...

Latest development: 21.09.2026 20:31

A fake GitHub page for github.com/LastPass-Authenticator delivered a ZIP containing vsdbg.exe and vsdbg.dll, then launched a Microsoft Windows Hardware Compatibility Publisher-signed Alinubx.sys kernel driver that terminated antivirus and other security processes before the stealer collected browser passwords, Windows Credential Manager data, cryptocurrency wallet files, and Discord, Steam, and Telegram sessions.

SEO-optimized GitHub software-lure campaign pushing Rapuncel infostealer

Campaign
H score36 First: 18.09.2026 18:19 Last: 18.09.2026 18:19 Sources 1

About this happening: An ongoing SEO-optimized GitHub campaign is impersonating LastPass and at least 39 other companies to lure people searching for LastPass Authenticator and other do...

BengalSEO SEO poisoning campaign

Campaign
H score12 First: 08.09.2026 11:43 Last: 08.09.2026 11:43 Sources 1

How related: Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams.

About this happening: The BengalSEO operation now stands out as a long-running SEO poisoning campaign that funnels search users into MayaBot malware delivery and tech support scams. Dis...

ClickFix AmnesiaStealer distribution campaign targeting mac users

Campaign
H score22 First: 14.08.2026 13:45 Last: 14.08.2026 13:45 Sources 1

About this happening: A ClickFix campaign is distributing AmnesiaStealer to macOS users through a counterfeit GitHub "Download for macOS" page and a copy-and-paste command that launches...

Latest development: 16.08.2026 18:07

Jamf described AmnesiaStealer's stream_module and remote_stream commands, which copy a victim's Chromium profile into a hidden headless browser and open WebSocket and Chrome DevTools Protocol channels through webSocketDebuggerUrl. The operator can issue navigation and mouse commands, receive live screencasts, and export or import cookies to operate online portals inside the victim's authenticated sessions on Google Chrome, Microsoft Edge, Vivaldi, Arc, Opera, Brave, and Chromium.

XCSSET v40 macOS malware activity via compromised Xcode projects

Malware Activity
H score30 First: 04.08.2026 22:03 Last: 04.08.2026 22:03 Sources 1

About this happening: XCSSET v40 has resurfaced on macOS through compromised Xcode projects and GitHub repositories, putting thousands of users at risk of credential theft and data...

Timeline

  1. 08.09.2026 11:43 2 articles · 13d ago

    BengalSEO deploys MayaBot for command-and-control and XMRig mining

    Initial Disclosure

    Cybersecurity researchers disclosed that BengalSEO is a long-running SEO poisoning operation from Rajasthan, India, and that one of its payloads is MayaBot, a custom malware used since 2022 to provide command-and-control (C2), system monitoring, and XMRig cryptocurrency mining. The same operation uses lure pages, redirector chains, and a traffic distribution system to route victims into malware delivery or tech support scams.

    Show sources