HomeYoutubeHackers exploit the popularity of DeepSeek-R1

Hackers exploit the popularity of DeepSeek-R1

Kaspersky researchers have uncovered a new, highly sophisticated malicious campaign that exploits the growing popularity of large language models (LLMs), primarily targeting users looking to download DeepSeek-R1 .

According to the report, cybercriminals are leveraging malvertising through Google Ads and phishing techniques to distribute a new malware called BrowserVenom. The malware is designed to hijack web traffic and extract sensitive data from victims.

See also: Microsoft: Employees are not allowed to use DeepSeek

The attackers have created a deceptive website, deepseek-platform[.]com, that mimics the official DeepSeek page almost exactly. Through Google ads that appear at the top of results for searches such as “deepseek r1,” users are lured to the fake site.

Hackers exploit the popularity of DeepSeek-R1

Upon entering, visitors are directed to fake screens, as well as a CAPTCHA. Finally, they are prompted to download a supposed installer named “AI_Launcher_1.21.exe”.

However, along with the supposed installation of the DeepSeek AI tool, a malware dropper is activated in the background. The malware starts with an PowerShell commandAES-encryptedthat attempts to exclude the user's folder from Windows Defender scanning – a trick that increases the chances of the malware going unnoticed.

See also: DeepSeek updates its mathematical AI model Prover

BrowserVenom malware loads directly into memory

The installer used by the attackers downloads additional malicious payloads via obfuscated scripts, with the ultimate goal of loading BrowserVenom directly into the system's memory – a technique that bypasses traditional antivirus detection.

DeepSeek-R1 large language models
Hackers exploit the popularity of DeepSeek-R1

Once activated, BrowserVenom malware redirects all browser traffic through a proxy server controlled by cybercriminals. The interception of online activity is achieved by installing a fake SSL certificate and resetting settings in popular browsers such as Chrome, Edge, Firefox (and others based on Chromium and Gecko). To remain active even after system reboots, the malware modifies shortcuts and settings, ensuring its long-term presence on the target system.

See also: South Korea: DeepSeek transferred user data without consent

It is worth noting that analysts identified Russian language elements in the source code of the DeepSeek-R1 phishing websites and installation files, which reinforces the possibility of a Russian-speaking origin of the campaign.

The campaign is global in scope, with confirmed infections in countries including Brazil, Cuba, Mexico, India, Nepal, South Africa , and Egypt. The main proxy infrastructure, through which traffic is diverted, is located at 141.105.130[.]106, on port 37121, according to Kaspersky's findings.

Artificial Intelligence in the spotlight

The recent BrowserVenom malware incident confirms an increasingly worrying trend: cybercriminals are turning their attention to Artificial Intelligence . As large language models (LLMs) and AI tools become increasingly popular, they are becoming ideal bait for complex, international malicious campaigns.

Hackers exploit the popularity of DeepSeek-R1
Hackers exploit the popularity of DeepSeek-R1

Ways to protect against malware targeting AI tools

  • Download tools only from official sources (e.g. the project's GitHub or the creator's official site).
  • Avoid ads and sponsored links on search engines for software downloads.
  • Check the URL carefully and make sure it uses HTTPS with a valid SSL certificate.
  • Use antivirus software with real-time protection and up-to-date malware signatures.
  • Enable Microsoft Defender (or other AV) and avoid blocking folders via unknown scripts.
  • Avoid installing unknown .exe files without a digital signature.
  • Limit or disable extensions that change browser settings or proxy configs.
  • Regularly check browser settings your for suspicious changes (proxy, certificates, homepage).
  • Prefer virtual environments or sandboxes for testing AI software, especially if it is newly emerging.
  • Get informed from authoritative security sources (e.g. Kaspersky, ESET, CERT) about known phishing & malvertising campaigns.

Source: gbhackers.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS