DeepSeek Lure Used To Spread Malware
ID: d6c0501c-742f-5495-8132-d444164f84ad
STIX ID: report--d6c0501c-742f-5495-8132-d444164f84ad
Feed Name: Zscaler Security Research Blog
This report describes a malicious campaign that abused a DeepSeek-branded look-alike domain (deepseekcaptcha.top) and a fake CAPTCHA/verification flow that copies a PowerShell command to victims' clipboards; when executed the command downloads and launches a packed Vidar stealer (1.exe). The Vidar payload targets browser profiles and a long list of cryptocurrency wallet extensions and file patterns for data theft, and communicates with attacker infrastructure via Telegram, a Steam profile, and the IPs 77.239.117.222, 95.216.178.57, and 95.217.246.174.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
