logo

DeepSeek ClickFix Scam Exposed! Protect Your Data Before It’s Too Late

ID: 7487cd2a-4790-5bf5-ab53-e1f4b97ad119

STIX ID: report--7487cd2a-4790-5bf5-ab53-e1f4b97ad119

Feed Name: CloudSEK Blog

Threat Score
70/100

Date Published: 2025-02-10

Date Updated: 2026-04-27

...
...

Threat actors deployed a ClickFix phishing campaign impersonating DeepSeek that lures victims to a fake captcha domain (deepseekcaptcha.top) which copies and runs a PowerShell command to download and execute a Vidar Stealer 1st-stage downloader (1.exe). The report documents static analysis linking the sample to Vidar, notes C2/update mechanisms via IP hosts and a Steam profile, provides multiple IOCs (file hashes, IPs, domain, malicious Steam URL), and offers mitigation and user-awareness recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.