https://cairoict.com/trade-visitor-registration/ https://cairoict.com/trade-visitor-registration/ https://cairoict.com/trade-visitor-registration/
الخميس, 16 أبريل, 2026
سياسة الخصوصية
من نجن
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English
Techno fin
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English

Kaspersky Uncovers Deception Campaign Using Deep Seek AI

by تكنو فن
مارس 9, 2025
Reading Time: 3 mins read
A A
Kaspersky Uncovers Deception Campaign Using Deep Seek AI

Security researchers at Kaspersky have revealed how cybercriminals used geofencing, compromised business accounts and coordinated bot networks to distribute malware disguised as DeepSeek AI software, generating over 1.2 million views on X.

Kaspersky’s Threat Research and AI Technology Research have jointly identified a sophisticated deception campaign exploiting the rapid growth and public interest surrounding DeepSeek AI — a popular generative AI chatbot — in order to distribute malware through fraudulent websites.

In their investigation, Kaspersky researchers revealed that cybercriminals established deceptive replicas of the official DeepSeek website, using domain names like “deepseek-pc-ai[.]com” and “deepseek-ai-soft[.]com.” A distinctive feature of this campaign was its use of geofencing technology, where malicious websites examine each visitor’s IP address and dynamically alter content presentation based on geographic location, enabling attackers to fine-tune their approach and reduce detection risks.

“This campaign demonstrates notable sophistication beyond typical social engineering attacks,” explained Vasily Kolesnikov, senior malware analyst at Kaspersky Threat Research. “Attackers exploited the current hype around generative AI technology, skillfully combining targeted geofencing, compromised business accounts and orchestrated bot amplification to reach a substantial audience while carefully evading cybersecurity defenses.”

RelatedPosts

“Raising Good Gamers” is a global program that teaches parents the secrets of video games”

Google Launches “Personal Intelligence” Feature for Gemini Users Across the Arab Region

LG Expands Partnership with WATCH IT to Boost Arabic Content Across LG Channels and webOS

According to Kaspersky’s analysis, the campaign’s primary distribution channel was the social media platform X. Attackers strategically compromised the social media account of a legitimate Australian company to widely disseminate fraudulent links. This single malicious post drew significant attention, reaching approximately 1.2 million impressions and generating hundreds of reposts. Researchers determined that these reposts largely originated from coordinated bot accounts — evident due to their similar naming conventions and profile characteristics — indicating a deliberate amplification of the malicious content.

Visitors lured to the fraudulent websites were directed to download a fabricated DeepSeek client application. Instead of the authentic software, these sites delivered malicious installers using the Inno Setup installation platform. Once executed, these compromised installers attempted to contact remote command-and-control servers to retrieve Base64-encoded PowerShell scripts. These scripts subsequently activated Windows’ built-in SSH service, reconfigured it with attacker-controlled keys and enabled full remote unauthorized access to compromised systems.

All malware payloads connected to this campaign are proactively identified and blocked by Kaspersky security products such as Trojan-Downloader.Win32.TookPS.* variants.

To remain secure, Kaspersky advises people to do the following:

  • Check URLs meticulously. Fraudulent AI websites often use domain names that closely resemble legitimate services but contain subtle differences. Before downloading any AI software, verify that the website URL exactly matches the official domain with no additional words, hyphens or spelling variations.
  • Use comprehensive security protection. Deploy a robust security solution like Kaspersky Premium on all devices to detect and block malicious installers and websites before they can compromise your system.
  • Keep all software updated. Many security vulnerabilities exploited by malware can be addressed by installing the latest versions of your operating system and applications, particularly security software.

شارك هذا الموضوع

  • المشاركة على WhatsApp (فتح في نافذة جديدة) WhatsApp
  • المشاركة على Telegram (فتح في نافذة جديدة) Telegram
  • المزيد
  • تدوينة
  • Tweet

مرتبط

Tags: Cybercriminals attackDeepSeekKasperskymalware

Related Posts

Raising Good Gamers
English

“Raising Good Gamers” is a global program that teaches parents the secrets of video games”

أبريل 15, 2026
“Gemini”
English

Google Launches “Personal Intelligence” Feature for Gemini Users Across the Arab Region

أبريل 15, 2026
LG Channels
English

LG Expands Partnership with WATCH IT to Boost Arabic Content Across LG Channels and webOS

أبريل 15, 2026
سي شور هايد بارك Hyde Park
English

Hyde Park Develops New “Shore Residences” Phase in Seashore Project in Ras El Hekma

أبريل 15, 2026
Load More

آخر الأخبار

Raising Good Gamers

“Raising Good Gamers” is a global program that teaches parents the secrets of video games”

أبريل 15, 2026
“Gemini”

Google Launches “Personal Intelligence” Feature for Gemini Users Across the Arab Region

أبريل 15, 2026
Facebook Messenger

بكرة آخر يوم.. ميتا تقفل موقع Messenger رسميًا

أبريل 15, 2026
صفقة ضخمة.. أحمد طارق يعزز ملكيته في “المطورون العرب” بمئات الملايين من الأسهم

صفقة ضخمة.. أحمد طارق يعزز ملكيته في “المطورون العرب” بمئات الملايين من الأسهم

أبريل 15, 2026
LG Channels

LG Expands Partnership with WATCH IT to Boost Arabic Content Across LG Channels and webOS

أبريل 15, 2026
No Result
View All Result
contact us: info@techno-fin.com Dubai:0553028804 Cairo:01150009990

Follow Us

All rights reserved to www.techno-fin.com, UAE, Sheikh Zayed Road, City Tower 2, 18th floor, office 1801
No Result
View All Result
  • آخر الأخبار
  • أمن إلكتروني
  • خدمات مالية
  • تقنيات ومنصات
  • ريادة أعمال
  • عالم الألعاب
  • مدن المستقبل
  • أحدث المنتجات
  • ترند
  • English