NewsdeckNewsdeck
  • Home
  • News
  • Politics
  • Business
  • Entertainment
  • Sports
  • Tech
  • About Us 
    • Contact Us
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
NewsdeckNewsdeck
Subscribe
  • Home
  • News

    Mother’s Day: Ajadi Commends Nigerian Women For Their Pivotal Roles, Says They Are Unsung Heroes

    March 31, 2025

    Italy-Based Businessman Arrested Over Illicit Drug Importation

    March 31, 2025

    Eid-el-fitr: FG Declares Public Holidays

    March 27, 2025

    Hotel Review Scam: EFCC Arraigns Four Chinese and Nigerian in Abuja

    March 26, 2025

    EFCC Busts Ponzi Scheme Academy,  Arrests 133 Suspects in Abuja

    March 24, 2025
  • Politics

    Okpoko Transformation from Slum to Opulent Area, Soludo’s Urban Renewal Wonder

    March 21, 2025

    Senate Approves Tinubu’s Emergency Rule In Rivers State

    March 21, 2025

    Tinubu Declares State of Emergency in Rivers State

    March 18, 2025

    Jandor Returns To APC

    March 18, 2025

    Rivers Assembly Commences Impeachment Process Against Fubara, Deputy 

    March 17, 2025
  • Business

    Diamond Bank’s Founder, Pascal Dozie Passes Away on Eve of 86th Birthday

    April 8, 2025

    A Life Of Purpose: My 50-Year Journey Of Impact, Gratitude And Philanthropy 

    April 2, 2025

    Tinubu Sacks NNPC Boss, Mele Kyari, Board of Directors, Appoints Ojulari 

    April 2, 2025

    Dangote, Adenuga, Rabiu, Otedola on Forbes’ 2025 African Billionaires List

    March 31, 2025

    Ramadan Delight: Enjoy Flexible Payments, Huge Discounts & Exclusive Gifts with Adron Homes

    March 26, 2025
  • Entertainment

    “I Don’t Need You At My Birthday Party,” Lizzy Anjorin Blasts Tope Alabi 

    April 5, 2025

    2026 WCQ: Nigeria and Zimbabwe Draw 1-1 in Uyo

    March 25, 2025

    EFCC Arrests Kano TikTok Influencer, Murja Kunya for Alleged Naira Mutilation

    March 17, 2025

    Court Hears Nurse’s Testimony on Mohbad’s Death

    March 15, 2025

     Defamation: Court Orders VeryDarkMan’s Arrest

    March 13, 2025
  • Sports

    Erling Haaland Out For 7 Weeks

    April 2, 2025

    2026 WCQ: Nigeria and Zimbabwe Draw 1-1 in Uyo

    March 25, 2025

    FIFA WCQ: Osimhen Scores Twice as Nigeria Defeats Rwanda 2-0

    March 22, 2025

    2026 WCQ: Super Eagles Camp Now Complete with Yusuf’s Arrival

    March 21, 2025

    Arsenal’s Win Over Chelsea Keeps Slim Title Hopes Alive

    March 17, 2025
  • Tech

    OpenAI Raises $40b at $300bn Post-Money Valuation

    April 2, 2025

    Senate Calls for Review of Data Price Hikes

    March 27, 2025

    How To Prevent A Whatsapp Account From Being Hacked: Kaspersky Recommendations

    March 22, 2025

    Kaspersky Uncovers Sophisticated Deception Campaign Using DeepSeek AI As Bait

    March 10, 2025

    Nigerian Leading Women Entrepreneurs Named Among Aurora Tech Award 2025 Finalists

    March 5, 2025
  • About Us 
    • Contact Us
NewsdeckNewsdeck
Home » Kaspersky Uncovers Sophisticated Deception Campaign Using DeepSeek AI As Bait
Headlines

Kaspersky Uncovers Sophisticated Deception Campaign Using DeepSeek AI As Bait

NewsdeckBy NewsdeckMarch 10, 2025No Comments3 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Kaspersky uncovers deception campaign using DeepSeek AI as bait
Share
Facebook Twitter LinkedIn Pinterest Email

Security researchers at Kaspersky have revealed how cybercriminals used geofencing, compromised business accounts and coordinated bot networks to distribute malware disguised as DeepSeek AI software, generating over 1.2 million views on X.

Kaspersky’s Threat Research and AI Technology Research have jointly identified a sophisticated deception campaign exploiting the rapid growth and public interest surrounding DeepSeek AI — a popular generative AI chatbot — in order to distribute malware through fraudulent websites.

In their investigation, Kaspersky researchers revealed that cybercriminals established deceptive replicas of the official DeepSeek website, using domain names like “deepseek-pc-ai[.]com” and “deepseek-ai-soft[.]com.” A distinctive feature of this campaign was its use of geofencing technology, where malicious websites examine each visitor’s IP address and dynamically alter content presentation based on geographic location, enabling attackers to fine-tune their approach and reduce detection risks.

“This campaign demonstrates notable sophistication beyond typical social engineering attacks,” explained Vasily Kolesnikov, senior malware analyst at Kaspersky Threat Research. “Attackers exploited the current hype around generative AI technology, skillfully combining targeted geofencing, compromised business accounts and orchestrated bot amplification to reach a substantial audience while carefully evading cybersecurity defenses.”

According to Kaspersky’s analysis, the campaign’s primary distribution channel was the social media platform X. Attackers strategically compromised the social media account of a legitimate Australian company to widely disseminate fraudulent links. This single malicious post drew significant attention, reaching approximately 1.2 million impressions and generating hundreds of reposts. Researchers determined that these reposts largely originated from coordinated bot accounts — evident due to their similar naming conventions and profile characteristics — indicating a deliberate amplification of the malicious content.

Visitors lured to the fraudulent websites were directed to download a fabricated DeepSeek client application. Instead of the authentic software, these sites delivered malicious installers using the Inno Setup installation platform. Once executed, these compromised installers attempted to contact remote command-and-control servers to retrieve Base64-encoded PowerShell scripts. These scripts subsequently activated Windows’ built-in SSH service, reconfigured it with attacker-controlled keys and enabled full remote unauthorised access to compromised systems.

All malware payloads connected to this campaign are proactively identified and blocked by Kaspersky security products such as Trojan-Downloader.Win32.TookPS.* variants.

To remain secure, Kaspersky advises people to do the following:

·         Check URLs meticulously. Fraudulent AI websites often use domain names that closely resemble legitimate services but contain subtle differences. Before downloading any AI software, verify that the website URL exactly matches the official domain with no additional words, hyphens or spelling variations.

·         Use comprehensive security protection. Deploy a robust security solution like Kaspersky Premium on all devices to detect and block malicious installers and websites before they can compromise your system.

·         Keep all software updated. Many security vulnerabilities exploited by malware can be addressed by installing the latest versions of your operating system and applications, particularly security software.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Newsdeck
  • Website

Related Posts

Diamond Bank’s Founder, Pascal Dozie Passes Away on Eve of 86th Birthday

April 8, 2025

“I Don’t Need You At My Birthday Party,” Lizzy Anjorin Blasts Tope Alabi 

April 5, 2025

A Life Of Purpose: My 50-Year Journey Of Impact, Gratitude And Philanthropy 

April 2, 2025

Comments are closed.

Diamond Bank’s Founder, Pascal Dozie Passes Away on Eve of 86th Birthday

April 8, 2025

“I Don’t Need You At My Birthday Party,” Lizzy Anjorin Blasts Tope Alabi 

April 5, 2025

A Life Of Purpose: My 50-Year Journey Of Impact, Gratitude And Philanthropy 

April 2, 2025

Tinubu Sacks NNPC Boss, Mele Kyari, Board of Directors, Appoints Ojulari 

April 2, 2025
Facebook X (Twitter) Instagram Pinterest
Copyright © Newsdeck 2025. All Rights Reserved | Proudly Designed By DeedsTech.

Type above and press Enter to search. Press Esc to cancel.