Malware authors are exploiting popular trending terms like "AI" and "DeepSeek" to lure unsuspecting users into installing malware through tactics like SEO poisoning and affiliate programs.
AI tools, such as chatbots, voice cloning software, and text generators, have become common, making it easier for scammers to create deepfake videos, impersonate voices, and conduct phishing scams.
Scammers capitalized on the hype around DeepSeek-R1 model release, launching fake DeepSeek AI assistant apps that prompted major downloads while disguising malware.
Users encountered threats like fake installers, trojanized applications, and fake captcha pages disguised as DeepSeek software, distributing malware like Keyloggers, Crypto miners, and Password Stealers.
McAfee uncovered various DeepSeek-themed malware campaigns attempting to exploit the popularity, targeting tech-savvy users by masquerading as legitimate software.
Examples included fake installers distributing third-party software, fake Android apps abusing the DeepSeek logo, and fake captcha pages leading to malicious software downloads.
A technical analysis revealed cryptominer malware posing as DeepSeek, using techniques like process injection, persistence, and payload execution to mine Monero cryptocurrency for anonymity.
The malware attempted system infiltration and resource exploitation by connecting to a C2 server, downloading malicious scripts, and initiating mining processes through legitimate Windows processes.
McAfee advises caution when encountering trending news stories, underscores the importance of protection features like Scam Protection, Web Protection, and Antivirus, and offers AI-powered security solutions.
By staying informed, being vigilant online, and utilizing security measures like McAfee's offerings, users can outsmart scammers and contribute to making the internet a safer space for everyone.