Threat Research

    The blog highlights how malware creators exploit popular trends, such as "AI" and "DeepSeek," to deceive unsuspecting users into downloading malicious software. By manipulating search engine optimization (SEO) and using trending keywords, cybercriminals boost the visibility of malicious sites....
    A campaign in February and March 2025 registered over 2,000 malicious domains to distribute trojanized installers disguised as Chinese language software, including DeepSeek AI Assistant, i4Tools, and Youdao Dictionary. While the installers appear legitimate, they infect Windows hosts with malware, potentially Ghost RAT (gh0st RAT)....
    The DeepSeek AI chatbot, launched on January 20, 2025, quickly became a target for abuse. Threat actors use brand impersonation tactics to create fraudulent websites that trick users into revealing sensitive information or executing malware....
    Following the release of DeepSeek's LLM, several newly registered domains (NRDs) linked to phishing sites have emerged. Domains such as deepseeklogin[.]com are designed to imitate the official DeepSeek homepage, featuring fake login pages that prompt victims to enter their credentials....
    Looking for Something?
    Threat Research Categories:
    Tags