Hackers Use Fake DeepSeek TUI GitHub Repositories to Deliver Malware
ID: ac2969be-b7f4-5048-9bae-978610966c2f
STIX ID: report--ac2969be-b7f4-5048-9bae-978610966c2f
Feed Name: cybersecurityNews.com
Researchers identified a GitHub-based spoofing campaign delivering a Rust-written multi-stage malware masquerading as popular AI/open-source tools (notably DeepSeek TUI). The malware performs sandbox checks, disables Defender protections, establishes persistence via scheduled tasks and registry Run keys, loads .NET assemblies in memory, communicates with Pastebin/snippet.host and specified C2 domains, and uses Telegram for reporting; the report includes numerous MD5 hashes, domains, and staging URLs as IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
