logo

Toxic trend: Another malware threat targets DeepSeek

ID: 5ae19b21-698f-5770-a1df-606d661138c7

STIX ID: report--5ae19b21-698f-5770-a1df-606d661138c7

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2025-06-11

Date Updated: 2026-04-29

Author: Lisandro Ubiedo

...
...

Kaspersky describes a malvertising campaign that impersonates the DeepSeek-R1 website to distribute a malicious Windows installer (AI_Launcher_1.21.exe). The installer runs a multi-stage infection that deploys BrowserVenom, an implant that installs a malicious root certificate, modifies Chromium/Gecko browser settings and shortcuts to route traffic through an attacker-controlled proxy (141.105.130.106:37121), and thereby intercepts and decrypts users’ browsing traffic. The chain includes AES-encrypted payloads, PowerShell commands attempting Defender exclusion, a DGA-based downloader, and in-memory execution; infections were observed across multiple countries and detections are reported as HEUR:Trojan.Win32.Generic and Trojan.Win32.SelfDel.iwcv.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.