Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page to Deliver Malware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Chinese-speaking cybercriminals are using fake software pages that imitate popular artificial intelligence tools to infect Windows users with remote access malware.

The campaign turns interest in DeepSeek into a trap, offering what looks like a normal download but delivering an installer built to hide its real purpose.

The operation also impersonates Quark Cloud and Pony Activator, widening the number of people who might trust the download.

Once the installer runs, it launches a chain designed to weaken security controls and give attackers a foothold that can be used for surveillance, theft, or further malware delivery.

Analysts at Zscaler ThreatLabz identified the activity and linked it to a Chinese-speaking cybercrime group.

Zscaler ThreatLabz said in a report shared with Cyber Security News (CSN) that the group used AI-generated portals to make its imitation download pages more convincing.

The case shows how quickly a well-known AI name can become a lure. It also underlines a familiar risk: a polished page and a familiar logo do not prove that a download is genuine, particularly when it comes from an advert, a search result, or an unexpected link.

For defenders, the campaign is a reminder that prevention begins before an infection: verify download channels, keep users from running unapproved installers, and make sure security tooling cannot be easily disabled by vulnerable components. Fast review of suspicious installs can quickly limit harm.

Chinese-speaking Hacking Group Attacking Users With Fake DeepSeek Page

The first stage is a Windows Installer package, or MSI, made with the WiX toolkit. Its custom action starts malicious code rather than simply installing an application.

That choice helps the file resemble ordinary setup software while preparing the system for activity the victim cannot easily see.

The installer decrypts further payloads directly in memory, a method that limits the useful traces left on disk.

That makes an investigation harder and can delay alerts. Similar lures have appeared in malvertising against DeepSeek users, where lookalike sites sent visitors to harmful downloads.

After this step, the attackers use a signed but vulnerable Adlice TrueSight version 2.0.2 driver to terminate more than 200 security products, according to the researchers.

A driver runs very deeply inside Windows, so abusing one can let malware interfere with protections that would otherwise stop or flag it.

This is not just a technical detail. When endpoint protection is switched off, a criminal can work with far less visibility, leaving both personal information and business systems exposed.

Recent security driver abuse campaigns illustrate why defenders increasingly watch unusual driver loads as closely as suspicious executables.

Gh0st RAT Raises the Stakes

With defenses impaired, the campaign deploys a variant of Gh0st RAT, a remote access trojan. Such malware can let an operator control an infected computer from afar.

The immediate impact may include stolen files, screen monitoring, command execution, or use of the machine as a launch point for other intrusions.

The group’s use of several familiar software names is important because it broadens the pool of potential victims beyond dedicated AI users.

Developers, students, and office workers may all search for utilities or cloud services. The same social engineering pattern appears in fake AI repository downloads, which use trusted-looking project pages to distribute harmful files.

People should download software only from the vendor’s verified website or a confirmed official store, and they should treat unexpected MSI files as a warning sign.

Organizations should restrict who can install software and review alerts for unsigned or unusual driver installation, security-service termination, and installers that launch hidden child processes.

Security teams should also keep Windows and endpoint controls current, enable the vulnerable-driver blocklist where appropriate, and investigate any sudden loss of protection.

Broader reporting on the abuse of signed drivers shows that a valid signature alone is no guarantee that a driver is safe in context.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world