A fake AI assistant named DeepSeek-R1 is being used to distribute malware and steal user data as discovered by researchers at Kaspersky.
The fraudulent campaign involves fake websites and paid Google ads that redirect users to a website posing as the legitimate DeepSeek platform to trick them into downloading malware.
The installed malware bypasses Windows Defender, manipulates web browsers to route traffic through a controlled proxy, allowing cybercriminals to spy on users and steal sensitive data.
Users are advised to verify the source of downloads, especially for AI tools, to mitigate such risks as cybercriminals increasingly exploit the popularity of AI tools for malicious activities.