Criminals are spreading malware disguised as DeepSeek AI

Representational image of a cybercriminal
Image Credit: Pixabay (Image credit: Pixabay)

  • Fake DeepSeek websites are popping up and distributing malware
  • The sites are followed by a huge promotion campaign on X
  • The campaign generated more than a million views, experts warn

Cybercriminals are taking advantage of the hype surrounding AI hot-shot Deepseek to trick people into downloading malware, while evading scrutiny from security analysts, experts have warned.

Researchers at Kaspersky recently observed a sophisticated campaign consisting of compromised X accounts, coordinated bot activity, and geofencing.

The researchers said the cybercriminals created multiple websites to mimic the original Deepseek page. They set the pages up in such a way that they analyzed every visitor’s IP address, and altered the content dynamically, based on the location of the visitor. That way, they were able to display malicious content to some people, and benign content to others.

The targets were shown fake Deepseek software which granted the attackers full remote unauthorized access to their computers.

The hackers also got to advertising - stealing an X account belonging to a legitimate Australian company, and posted content that promoted the fake websites. They used a network of X bots to comment and share the content, generating more than a million views on the microblogging platform.

"Notable sophistication"

"This campaign demonstrates notable sophistication beyond typical social engineering attacks," explained Vasily Kolesnikov, senior malware analyst at Kaspersky Threat Research.

"Attackers exploited the current hype around generative AI technology, skillfully combining targeted geofencing, compromised business accounts and orchestrated bot amplification to reach a substantial audience while carefully evading cybersecurity defenses."

This is yet another proof that internet buzz does not translate to legitimacy. Cybercriminals are getting better at faking engagement, inflating download numbers, and writing fraudulent positive reviews.

To remain safe on the internet, one must be vigilant at all times. Do not trust - verify, should be the mantra, as scam campaigns get more sophisticated and more difficult to spot.

Software should always be downloaded from legitimate sources, whose URLs need to be checked meticulously. Finally, one should have a security program set up, and should keep their software up to date at all times.

You might also like

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
DeepSeek
Experts warn DeepSeek is 11 times more dangerous than other AI chatbots
A person using DeepSeek on their smartphone
DeepSeek ‘incredibly vulnerable’ to attacks, research claims
A laptop with digitally inserted hack warnings around it
Is DeepSeek AI safe to use? Think twice before you download DeepSeek for the time being
A concept image of someone typing on a computer. A red flashing danger sign is above the keyboard and nymbers and symbols also in glowing red surround it.
Fake Reddit sites found pushing Lumma Stealer malware
Trojan
Hackers hide malware into website images to go unnoticed
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
Latest in Security
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Latest in News
Representational image of a cybercriminal
Criminals are spreading malware disguised as DeepSeek AI
The logo of the social media app Bluesky is seen on the screen of a mobile phone
Bluesky gets a massive video upgrade to tempt X fans who are frustrated by its cyberattack outages
Acer Aspire 14 AI laptop display showing the Windows 11 login screen
Shock, horror – I’m not going to argue with Microsoft’s latest bit of nagging in Windows 11, as this pop-up is justified
Europe
Apple and Meta set to face fines for alleged breaches of EU DMA
Garmin Forerunner 965 on wrist in the dark
New Garmin leak suggests a release is days away, but don't get your hopes up for the Forerunner 975
Xbox Series X
Xbox is reportedly teaming up with a mystery manufacturer to launch a PC gaming handheld this year