logo

Bogus ‘DeepSeek’ AI Installers Are Infecting Devices with Malware, Research Finds

ID: 78294820-e849-5095-a12c-952e6cf63c15

STIX ID: report--78294820-e849-5095-a12c-952e6cf63c15

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2025-03-17

Date Updated: 2026-04-28

Author: Jasdev Dhaliwal

...
...

McAfee Labs reports that threat actors are exploiting the hype around a new AI product called “DeepSeek” to distribute malware via fake installers, repackaged third‑party apps, and fraudulent captcha pages; observed payloads include keyloggers, cryptominers, and the Vidar infostealer. The report highlights specific deceptive filenames, describes social‑engineering tactics that disable security or trick users into executing commands, and recommends downloading only from official sources, avoiding unknown commands, keeping software and security tools updated, and monitoring for performance anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.