Kaspersky researchers have uncovered a new, highly sophisticated malicious campaign that exploits the growing popularity of large language models (LLMs), primarily targeting users looking to download DeepSeek-R1 .
According to the report, cybercriminals are leveraging malvertising through Google Ads and phishing techniques to distribute a new malware called BrowserVenom. The malware is designed to hijack web traffic and extract sensitive data from victims.
See also: Microsoft: Employees are not allowed to use DeepSeek
The attackers have created a deceptive website, deepseek-platform[.]com, that mimics the official DeepSeek page almost exactly. Through Google ads that appear at the top of results for searches such as “deepseek r1,” users are lured to the fake site.

Upon entering, visitors are directed to fake screens, as well as a CAPTCHA. Finally, they are prompted to download a supposed installer named “AI_Launcher_1.21.exe”.
However, along with the supposed installation of the DeepSeek AI tool, a malware dropper is activated in the background. The malware starts with an PowerShell commandAES-encryptedthat attempts to exclude the user's folder from Windows Defender scanning – a trick that increases the chances of the malware going unnoticed.
See also: DeepSeek updates its mathematical AI model Prover
BrowserVenom malware loads directly into memory
The installer used by the attackers downloads additional malicious payloads via obfuscated scripts, with the ultimate goal of loading BrowserVenom directly into the system's memory – a technique that bypasses traditional antivirus detection.

Once activated, BrowserVenom malware redirects all browser traffic through a proxy server controlled by cybercriminals. The interception of online activity is achieved by installing a fake SSL certificate and resetting settings in popular browsers such as Chrome, Edge, Firefox (and others based on Chromium and Gecko). To remain active even after system reboots, the malware modifies shortcuts and settings, ensuring its long-term presence on the target system.
See also: South Korea: DeepSeek transferred user data without consent
It is worth noting that analysts identified Russian language elements in the source code of the DeepSeek-R1 phishing websites and installation files, which reinforces the possibility of a Russian-speaking origin of the campaign.
The campaign is global in scope, with confirmed infections in countries including Brazil, Cuba, Mexico, India, Nepal, South Africa , and Egypt. The main proxy infrastructure, through which traffic is diverted, is located at 141.105.130[.]106, on port 37121, according to Kaspersky's findings.
Artificial Intelligence in the spotlight
The recent BrowserVenom malware incident confirms an increasingly worrying trend: cybercriminals are turning their attention to Artificial Intelligence . As large language models (LLMs) and AI tools become increasingly popular, they are becoming ideal bait for complex, international malicious campaigns.

Ways to protect against malware targeting AI tools
- Download tools only from official sources (e.g. the project's GitHub or the creator's official site).
- Avoid ads and sponsored links on search engines for software downloads.
- Check the URL carefully and make sure it uses HTTPS with a valid SSL certificate.
- Use antivirus software with real-time protection and up-to-date malware signatures.
- Enable Microsoft Defender (or other AV) and avoid blocking folders via unknown scripts.
- Avoid installing unknown .exe files without a digital signature.
- Limit or disable extensions that change browser settings or proxy configs.
- Regularly check browser settings your for suspicious changes (proxy, certificates, homepage).
- Prefer virtual environments or sandboxes for testing AI software, especially if it is newly emerging.
- Get informed from authoritative security sources (e.g. Kaspersky, ESET, CERT) about known phishing & malvertising campaigns.
Source: gbhackers.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
