Saturday, May 17, 2025
LBNN
  • Business
  • Markets
  • Politics
  • Crypto
  • Finance
  • Energy
  • Technology
  • Taxes
  • Creator Economy
  • Wealth Management
  • Documentaries
No Result
View All Result
LBNN

Cybercriminals Exploit DeepSeek AI Hype to Spread Malware via X

Simon Osuji by Simon Osuji
March 11, 2025
in Finance
0
Cybercriminals Exploit DeepSeek AI Hype to Spread Malware via X
0
SHARES
1
VIEWS
Share on FacebookShare on Twitter

Free Newsletter

Subscribe to the most important Fintech News Africa

Kaspersky’s security researchers have uncovered a sophisticated cybercriminal campaign that exploited the growing interest in DeepSeek AI, a popular generative AI chatbot, to distribute malware through fraudulent websites.

The campaign used geofencing, compromised business accounts and coordinated bot networks to evade detection and amplify its reach, generating over 1.2 million views on the social media platform X.

1.2 million views in a near-empty account? Smells like paid promotion
Source: Kaspersky

The investigation revealed that cybercriminals created deceptive replicas of the official DeepSeek website, using domain names such as “deepseek-pc-ai[.]com” and “deepseek-ai-soft[.]com.”

A key aspect of this operation was the use of geofencing, which enabled attackers to tailor the website’s content based on the visitor’s geographic location.

This approach helped them refine their tactics while reducing the likelihood of detection.

“This campaign demonstrates notable sophistication beyond typical social engineering attacks,”

explained Vasily Kolesnikov, senior malware analyst at Kaspersky Threat Research.

“Attackers exploited the current hype around generative AI technology, skillfully combining targeted geofencing, compromised business accounts and orchestrated bot amplification to reach a substantial audience while carefully evading cybersecurity defenses.”

Kaspersky’s analysis found that the campaign’s primary distribution method was social media, particularly X.

Attackers compromised the account of a legitimate Australian company to spread fraudulent links, which resulted in a single malicious post reaching approximately 1.2 million impressions and being widely shared.

Many of these reposts were traced to coordinated bot accounts, identified through similar naming conventions and profile characteristics, suggesting a deliberate effort to amplify the campaign’s reach.

Users who accessed the fraudulent websites were prompted to download a fake DeepSeek client application.

Instead of the legitimate software, the sites delivered malicious installers using the Inno Setup installation platform.

Once executed, these installers attempted to contact remote command-and-control servers, retrieving Base64-encoded PowerShell scripts.

These scripts then activated Windows’ built-in SSH service, reconfigured it with attacker-controlled keys and enabled full remote unauthorised access to the compromised systems.

All malware payloads linked to this campaign are “proactively identified and blocked by Kaspersky security products such as Trojan-Downloader.Win32.TookPS.* variants.”

To mitigate risks, Kaspersky advises users to verify URLs carefully before downloading AI software, ensuring that the domain matches the official website without alterations.

“Fraudulent AI websites often use domain names that closely resemble legitimate services but contain subtle differences.”

Additionally, deploying comprehensive security solutions, such as Kaspersky Premium, can help detect and block malicious websites and installers. Keeping all software updated is also essential, as

“many security vulnerabilities exploited by malware can be addressed by installing the latest versions of your operating system and applications, particularly security software.”

 

Featured image credit: edited from freepik



Source link

Related posts

Why Africa’s resource strategy needs rapid policy shift

Why Africa’s resource strategy needs rapid policy shift

May 16, 2025
Why Africa’s Fintech Ecosystems Must Unite to Shape the Future of Crypto, AI and Passporting Across the Continent

Why Africa’s Fintech Ecosystems Must Unite to Shape the Future of Crypto, AI and Passporting Across the Continent

May 16, 2025
Previous Post

Nigeria’s oil sector catches the attention of 76 Chinese companies

Next Post

Oman’s OQAE has 7GW of clean energy projects under development

Next Post
Oman’s OQAE has 7GW of clean energy projects under development

Oman’s OQAE has 7GW of clean energy projects under development

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

LG S95TR 9.1.5 Soundbar System Review: Perfect Audio for Your OLED

LG S95TR 9.1.5 Soundbar System Review: Perfect Audio for Your OLED

9 months ago
Cipla’s takeover by Capital Works stirs Uganda market

Cipla’s takeover by Capital Works stirs Uganda market

1 year ago
Google’s Visual Search Can Now Answer Even More Complex Questions

Google’s Visual Search Can Now Answer Even More Complex Questions

8 months ago
Top 10 African countries with the highest cost of diesel in October 2024

Top 10 African countries with the highest cost of diesel in October 2024

7 months ago

POPULAR NEWS

  • Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    0 shares
    Share 0 Tweet 0
  • When Will SHIB Reach $1? Here’s What ChatGPT Says

    0 shares
    Share 0 Tweet 0
  • Matthew Slater, son of Jackson State great, happy to see HBCUs back at the forefront

    0 shares
    Share 0 Tweet 0
  • Dolly Varden Focuses on Adding Ounces the Remainder of 2023

    0 shares
    Share 0 Tweet 0
  • US Dollar Might Fall To 96-97 Range in March 2024

    0 shares
    Share 0 Tweet 0
  • Privacy Policy
  • Contact

© 2023 LBNN - All rights reserved.

No Result
View All Result
  • Home
  • Business
  • Politics
  • Markets
  • Crypto
  • Economics
    • Manufacturing
    • Real Estate
    • Infrastructure
  • Finance
  • Energy
  • Creator Economy
  • Wealth Management
  • Taxes
  • Telecoms
  • Military & Defense
  • Careers
  • Technology
  • Artificial Intelligence
  • Investigative journalism
  • Art & Culture
  • Documentaries
  • Quizzes
    • Enneagram quiz
  • Newsletters
    • LBNN Newsletter
    • Divergent Capitalist

© 2023 LBNN - All rights reserved.