logo

Hackers Use Fake DeepSeek TUI GitHub Repositories to Deliver Malware

ID: ac2969be-b7f4-5048-9bae-978610966c2f

STIX ID: report--ac2969be-b7f4-5048-9bae-978610966c2f

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Tushar Subhra Dutta

...
...

Researchers identified a GitHub-based spoofing campaign delivering a Rust-written multi-stage malware masquerading as popular AI/open-source tools (notably DeepSeek TUI). The malware performs sandbox checks, disables Defender protections, establishes persistence via scheduled tasks and registry Run keys, loads .NET assemblies in memory, communicates with Pastebin/snippet.host and specified C2 domains, and uses Telegram for reporting; the report includes numerous MD5 hashes, domains, and staging URLs as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.