Fake DeepSeek installers are infecting your device with dangerous malware


- McAfee’s researchers find a “cocktail” of malware hiding behind fake DeepSeek apps
- The campaign preys on people searching for the generative AI tool
- Infostealers, crypto miners, and more, are being deployed this way
The hype around DeepSeek is the next big thing cybercriminals are exploiting in their hacking campaigns, researchers from McAfee Labs are saying.
The team has outlined how they saw cybercriminals setting up various websites, offering different versions of DeepSeek for download. Victims would reach these websites through search engines, meaning that some SEO poisoning was involved in the campaign, as well.
When they reach the websites and download the software, the victims are infected with a “cocktail of malware”, ranging from keyloggers and password stealers, to coin miners. These malware variants can steal sensitive information (including banking credentials and cryptocurrency wallet information), and can force the infected computer to mine cryptocurrency, rendering it useless for pretty much anything else.
You may like
Fake CAPTCHA
While on some websites, the victims are invited to download a DeepSeek app or program, on others – the devil is in the CAPTCHA.
In some cases observed by McAfee, victims would visit a website with a CAPTCHA that can be “solved” by copying and pasting a command into the Run program on Windows. This command just downloads and runs a malware dropper.
To stay safe, you should stay vigilant at all times. Instead of “googling” for something, visit the website directly, and if you don’t know the address, scrutinize every link returned by the search engine.
Furthermore, a real CAPTCHA will never ask you to paste a command into the Run program.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Hackers are known for tapping into current trends to distribute malware. Similar campaigns were observed when Chat-GPT was first released, both for Windows and Android.
Major events, such as Black Friday and Cyber Monday, the Olympic Games, World Cup, and others, have all been abused in the past. The Covid-19 breakout, Russo-Ukrainian war, and the US presidential elections, all served as platforms for information theft, malware distribution, and wire fraud.
You might also like
McAfee’s researchers find a “cocktail” of malware hiding behind fake DeepSeek apps The campaign preys on people searching for the generative AI tool Infostealers, crypto miners, and more, are being deployed this way The hype around DeepSeek is the next big thing cybercriminals are exploiting in their hacking campaigns, researchers…
Recent Posts
- Not Just Any Prime Day Deals, 255 Obsessively Tested Picks—Even $1,200 Off an OLED TV
- Why the AI boom requires an Wyatt Earp
- The four-phase security approach to keep in mind for your AI transformation
- Musk makes grand promises about Grok 4 in the wake of a Nazi chatbot meltdown
- Tempur-Pedic Promo Codes: Up to 50% Off
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022