logo

DeepSeek Lure Used To Spread Malware

ID: d6c0501c-742f-5495-8132-d444164f84ad

STIX ID: report--d6c0501c-742f-5495-8132-d444164f84ad

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This report describes a malicious campaign that abused a DeepSeek-branded look-alike domain (deepseekcaptcha.top) and a fake CAPTCHA/verification flow that copies a PowerShell command to victims' clipboards; when executed the command downloads and launches a packed Vidar stealer (1.exe). The Vidar payload targets browser profiles and a long list of cryptocurrency wallet extensions and file patterns for data theft, and communicates with attacker infrastructure via Telegram, a Steam profile, and the IPs 77.239.117.222, 95.216.178.57, and 95.217.246.174.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.