logo

Trojans disguised as AI: Cybercriminals exploit DeepSeek’s popularity

ID: 8b6de7db-36cb-5008-8c8b-e688c3e32cd3

STIX ID: report--8b6de7db-36cb-5008-8c8b-e688c3e32cd3

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2025-03-06

Date Updated: 2026-04-29

Author: Vladislav Tushkanov, Vasily Kolesnikov, Oleg Kupreev, Denis Sitchikhin, Alexander Kryazhev

...
...

Kaspersky researchers discovered multiple widespread campaigns using fake DeepSeek/Grok websites and social-media posts to distribute malicious installers and archives that deploy a Python-based stealer, PowerShell-based downloaders that enable SSH backdoors, DLL-sideloaded loaders, and KCP backdoors. The report details three schemes, technical indicators (MD5s and domains), distribution vectors (including an X post with 1.2M views), and recommends vigilance because victims may lose account credentials, cryptocurrency, and potentially expose corporate credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.