DeepSeek ClickFix Scam Exposed! Protect Your Data Before It’s Too Late
ID: 7487cd2a-4790-5bf5-ab53-e1f4b97ad119
STIX ID: report--7487cd2a-4790-5bf5-ab53-e1f4b97ad119
Feed Name: CloudSEK Blog
Threat actors deployed a ClickFix phishing campaign impersonating DeepSeek that lures victims to a fake captcha domain (deepseekcaptcha.top) which copies and runs a PowerShell command to download and execute a Vidar Stealer 1st-stage downloader (1.exe). The report documents static analysis linking the sample to Vidar, notes C2/update mechanisms via IP hosts and a Steam profile, provides multiple IOCs (file hashes, IPs, domain, malicious Steam URL), and offers mitigation and user-awareness recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
