Source |
Cyble |
Identifiant |
8646797 |
Date de publication |
2025-01-30 13:00:34 (vue: 2025-02-04 12:08:08) |
Titre |
DeepSeek\'s Growing Influence Sparks a Surge in Frauds and Phishing Attacks |
Texte |
Overview
DeepSeek is a Chinese artificial intelligence company that has developed open-source large language models (LLMs). In January 2025, DeepSeek launched its first free chatbot app, “DeepSeek - AI Assistant”, which rapidly became the most downloaded free app on the iOS App Store in the United States, surpassing even OpenAI\'s ChatGPT.
However, with rapid growth comes new risks-cybercriminals are exploiting DeepSeek\'s reputation through phishing campaigns, fake investment scams, and malware disguised as DeepSeek. This analysis seeks to explore recent incidents where Threat Actors (TAs) have impersonated DeepSeek to target users, highlighting their tactics and how readers can secure themselves accordingly.
Recently, Cyble Research and Intelligence Labs (CRIL) identified multiple suspicious websites impersonating DeepSeek. Many of these sites were linked to crypto phishing schemes and fraudulent investment scams. We have compiled a list of the identified suspicious sites:
abs-register[.]com
deep-whitelist[.]com
deepseek-ai[.]cloud
deepseek[.]boats
deepseek-shares[.]com
deepseek-aiassistant[.]com
usadeepseek[.]com
Campaign Details
Crypto phishing leveraging the popularity of DeepSeek
CRIL uncovered a crypto phishin |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
1024x512 2025 300x150 7d0e76c7682d33d36225620d3c82e4ddc0f6744baf387a0ea8124f968c185995 a3d06ffcb336cba72ae32e4d0ac5656400decfaf40dc28862de9289254a47698 abs accordingly account activities actors addition address advantage against agent aiassistant all already also always amos analysis analyzes analyzing android announced announcement announcements anti any app appear applications are artificial assistant” as amos stealer attackers attacks attempt audit avoid based became been before behind below below: best blacklisted boats boats/ button campaign campaigns can cannot capitalizing caption= carry cautious channels chatbot chatgpt check chinese claiming claims clear click closely cloud cloud/ code codes coin collecting com com/ com/wp comes common company compiled compromise compromised compromises compromising com” concerns conclusion confirm confirmed confirming connected connection consent content content/uploads/2025/01/cybleblogs continues contrary control could counterfeit create created creation cril crypto cryptocurrency cybercriminals cybersecurity cyble data deceive deceptive deep deepseek deepseekai deliver delivered delivering delivery description designed details detected developed development devices different discovered disguised display displayed displaying distribute domain downloaded downloading downloads e596da76aaf7122176eb6dac73057de4417b7c24378e00b10c468d7875a6e69e educate email emails emerged employees entirely entities essential establish even exploit exploited exploiting explore fake falsely figure file= filenames files financial first flag follow following found fraud frauds fraudulent free from funds gain given global growing growth harvest has have held highlighting highlights honeypot how however https://cyble hxxp://abs hxxps://deep hxxps://deepseek identifiable identified identity image impersonate impersonated impersonating importance incidents including increasingly indeed indicator indicators influence information intelligence intent interacting internet investment investors iocs ios ipo its itself january keep labs language laptop large later launch launched leading leads legitimacy legitimate leveraging like line linked links list listed llms loss losses lure luring made making malicious malware many media medium mentioned metamask mimic mislead mobile models most multiple must name new newly not now offer offers official often only open openai opening operating opportunity options organization others out overview package page personal personally phishing phishing/untrusted phone pii platform platforms png point popular popularity pose potential potentially practices pre presented presenting presents primary privacy privately project prominence promoting promotions prompt protecting provided purchase purchased raises rapid rapidly readers received recent recently recognition recognized recommend recommendations red redirect register registered remain reputation reputed research resulting rise rising risks samples scam scamming scams scanning scheme schemes screenshot secure security seeks selects sending sensitive serious serve several sha256 shares shown similar site sites sites: sms social software some source sources space spam sparks stage started starting states stay stealer store submit such suggesting surge surpassing suspicious systems tactics take target targeted tas theft them themselves these threat threats through title= token tokens total trade traps trending trick trust two type ultimately unable uncovered united unknown unsuspecting unverified updated upon urge url urls usadeepseek use user users using verify victims vigilance virus wallet walletconnect wallets wallet” wary website websites when where whether which whitelist who widely wild will windows withdraw without your “0x27238b76965387f5628496d1e4d2722b663d2698” “connect “deepseek |
Tags |
Spam
Malware
Threat
Mobile
|
Stories |
ChatGPT
|
Move |
|