Trojans disguised as AI: Cybercriminals exploit DeepSeek’s popularity
ID: 8b6de7db-36cb-5008-8c8b-e688c3e32cd3
STIX ID: report--8b6de7db-36cb-5008-8c8b-e688c3e32cd3
Feed Name: Securelist by Kaspersky
Date Published: 2025-03-06
Date Updated: 2026-04-29
Author: Vladislav Tushkanov, Vasily Kolesnikov, Oleg Kupreev, Denis Sitchikhin, Alexander Kryazhev
Kaspersky researchers discovered multiple widespread campaigns using fake DeepSeek/Grok websites and social-media posts to distribute malicious installers and archives that deploy a Python-based stealer, PowerShell-based downloaders that enable SSH backdoors, DLL-sideloaded loaders, and KCP backdoors. The report details three schemes, technical indicators (MD5s and domains), distribution vectors (including an X post with 1.2M views), and recommends vigilance because victims may lose account credentials, cryptocurrency, and potentially expose corporate credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
