3 Sources
[1]
'BrowserVenom' Windows Malware Preys on Users Looking to Run DeepSeek AI
It's possible to run some of today's AI chatbots locally on your PC. Just be careful: A newly discovered strain of Windows malware is exploiting interest in DeepSeek's AI models to infect victim computers. The attack delivers the "BrowserVenom" malware, which can secretly spy on and manipulate a
[2]
That DeepSeek installer you just clicked? It's malware
Suspected cybercriminals have created a fake installer for Chinese AI model DeepSeek-R1 and loaded it with previously unknown malware called "BrowserVenom". The malware's name reflects its ability to redirect all traffic from browsers through an attacker-controlled server. This enables the crooks
[3]
Watch out - that DeepSeek installer could be damaging malware
The malware relays sensitive data to attacker-controlled servers Cybersecurity researchers from Kaspersky have spotted a new malware distribution campaign abusing DeepSeek as a lure. In a report, the experts say unidentified hackers created a spoofed version of the DeepSeek-R1 website, on which
Share
Copy Link
A new malware campaign dubbed 'BrowserVenom' is exploiting interest in DeepSeek's AI models to infect Windows computers, potentially compromising user data and browsing activity.
A new malware campaign dubbed 'BrowserVenom' is targeting Windows users interested in running DeepSeek's AI models locally. Cybersecurity researchers at Kaspersky have uncovered this sophisticated attack that exploits the growing enthusiasm for AI technologies
1
.
Source: PC Magazine
The attackers are using Google Ads to promote fake websites that mimic the official DeepSeek platform. When users search for "deep seek r1" or related terms, these malicious ads appear at the top of search results, leading unsuspecting victims to a fraudulent domain: http[:]//deepseek-platform[.]com
2
.Upon visiting the fake website, users are prompted to download what appears to be the DeepSeek R1 model installer. The malicious file, named "AI_Launcher_1.21.exe," presents a convincing installation screen. However, it secretly installs the BrowserVenom malware, which reconfigures the victim's web browsers to route all traffic through a proxy server controlled by the attackers
1
.BrowserVenom is designed to:
3
Kaspersky has detected multiple infections across various countries, including Brazil, Cuba, Mexico, India, Nepal, South Africa, and Egypt. While the exact number of affected users remains undisclosed, the threat is considered global
2
.Related Stories
Analysis of the phishing websites' source code revealed comments in Russian, suggesting that Russian-speaking threat actors may be behind this campaign. However, no specific cybercrime group has been attributed to the attack
1
.To protect against such attacks, users are advised to:
3

Source: TechRadar
Google has reportedly suspended the advertiser's account responsible for promoting the malicious ads. However, the incident highlights the ongoing challenge of securing online advertising platforms against sophisticated cyber threats
2
.Summarized by
Navi
[2]
30 May 2025•Technology

12 May 2025•Technology

28 May 2026•Technology
