Fake DeepSeek installers are infecting your device with dangerous malware


- McAfee’s researchers find a “cocktail” of malware hiding behind fake DeepSeek apps
- The campaign preys on people searching for the generative AI tool
- Infostealers, crypto miners, and more, are being deployed this way
The hype around DeepSeek is the next big thing cybercriminals are exploiting in their hacking campaigns, researchers from McAfee Labs are saying.
The team has outlined how they saw cybercriminals setting up various websites, offering different versions of DeepSeek for download. Victims would reach these websites through search engines, meaning that some SEO poisoning was involved in the campaign, as well.
When they reach the websites and download the software, the victims are infected with a “cocktail of malware”, ranging from keyloggers and password stealers, to coin miners. These malware variants can steal sensitive information (including banking credentials and cryptocurrency wallet information), and can force the infected computer to mine cryptocurrency, rendering it useless for pretty much anything else.
You may like
Fake CAPTCHA
While on some websites, the victims are invited to download a DeepSeek app or program, on others – the devil is in the CAPTCHA.
In some cases observed by McAfee, victims would visit a website with a CAPTCHA that can be “solved” by copying and pasting a command into the Run program on Windows. This command just downloads and runs a malware dropper.
To stay safe, you should stay vigilant at all times. Instead of “googling” for something, visit the website directly, and if you don’t know the address, scrutinize every link returned by the search engine.
Furthermore, a real CAPTCHA will never ask you to paste a command into the Run program.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Hackers are known for tapping into current trends to distribute malware. Similar campaigns were observed when Chat-GPT was first released, both for Windows and Android.
Major events, such as Black Friday and Cyber Monday, the Olympic Games, World Cup, and others, have all been abused in the past. The Covid-19 breakout, Russo-Ukrainian war, and the US presidential elections, all served as platforms for information theft, malware distribution, and wire fraud.
You might also like
McAfee’s researchers find a “cocktail” of malware hiding behind fake DeepSeek apps The campaign preys on people searching for the generative AI tool Infostealers, crypto miners, and more, are being deployed this way The hype around DeepSeek is the next big thing cybercriminals are exploiting in their hacking campaigns, researchers…
Recent Posts
- Sony’s Brand New Flagship Headphones Are on Sale for Prime Day
- Ceramic-based startup wants to put more than 100,000TB in a 42U rack by 2030 — but it will take almost 50 years to fill it up
- The 35 best Prime Day deals you can get for under $25
- This is the weirdest looking AI MAX+ 395 Mini PC that I’ve ever seen — and you can apparently hold it comfortably in the palm of your hand
- The Columbia hack is a much bigger deal than Mamdani’s college application
Archives
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022