logo

DeepSeek installer or just malware in disguise? Click around and find out

ID: c5bf8cb9-6330-59c4-95a3-e124dcc53fd4

STIX ID: report--c5bf8cb9-6330-59c4-95a3-e124dcc53fd4

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2025-06-11

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Malicious actors used paid search ads and a fake DeepSeek-R1 site (deepseek-platform.com) to distribute a fake installer (AI_Launcher_1.21.exe from r1deepseek-ai.com) that deploys BrowserVenom — malware that installs a hardcoded certificate and forces browsers to use an attacker-controlled proxy, enabling credential/cookie theft and monitoring of plaintext traffic; Kaspersky observed infections across Brazil, Cuba, Mexico, India, Nepal, South Africa, and Egypt.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.