Chinese Hackers Use Fake DeepSeek Page to Deliver Malware
Key Takeaways A Chinese-speaking cybercrime group is distributing remote access malware through deceptive software download pages. The attackers impersonate legitimate AI tools like DeepSeek, Quark...
Key Takeaways
- A Chinese-speaking cybercrime group is distributing remote access malware through deceptive software download pages.
- The attackers impersonate legitimate AI tools like DeepSeek, Quark Cloud, and Pony Activator to trick Windows users into downloading malicious installers.
- The infection chain leverages a vulnerable, signed driver (Adlice TrueSight v2.0.2) to disable over 200 security products before deploying the Gh0st RAT.
- The campaign highlights the ongoing threat of supply chain attacks and the exploitation of trust in widely used software and AI platforms.
- Users and organizations must verify download sources, restrict software installations, and monitor for unusual system activities, especially driver loads and security service terminations.
Chinese Hackers Exploit AI Enthusiasm with Fake DeepSeek Pages to Deliver Malware
A sophisticated campaign orchestrated by a Chinese-speaking cybercrime group is leveraging fraudulent software download portals, mimicking popular artificial intelligence (AI) tools, to infect Windows users with potent remote access malware. The operation capitalizes on the growing interest in AI, presenting seemingly legitimate installers for applications such as DeepSeek, Quark Cloud, and Pony Activator, only to deliver a multi-stage malicious payload.
Table Of Content
The security researchers at Zscaler ThreatLabz said in a report that the threat actors utilized AI-generated content to enhance the authenticity of their deceptive download pages. This tactic allows the attackers to create convincing lures, turning genuine user interest in AI software into an unwitting conduit for malware distribution. The campaign underscores a critical and persistent risk: a professional-looking website or a familiar logo does not inherently validate the safety of a software download, particularly when sourced from advertisements, search engine results, or unexpected links.
The Deceptive Infection Chain
The initial stage of the attack involves a Windows Installer (MSI) package crafted using the WiX toolkit. Unlike standard software installers, this particular MSI incorporates a custom action designed to execute malicious code rather than simply installing an application. This subtle engineering helps the file blend in with legitimate setup software while covertly preparing the target system for subsequent malicious activities.
Upon execution, the installer decrypts additional payloads directly into memory, a technique that significantly reduces the forensic footprint left on disk. This stealthy approach complicates detection and analysis, potentially delaying security alerts and investigations. Zscaler ThreatLabz researchers further noted that similar lures have been observed in malvertising campaigns targeting DeepSeek users, directing them to harmful downloads via lookalike websites. pic.twitter.com/N51nl6qEDw
As detailed by Zscaler ThreatLabz on August 10, 2026, following the initial compromise, the attackers exploit a known vulnerability within a digitally signed driver: Adlice TrueSight version 2.0.2. This vulnerable driver is then used to forcibly terminate over 200 different security products installed on the victim’s system. Operating deep within the Windows kernel, drivers possess elevated privileges, allowing attackers to effectively neutralize endpoint protection mechanisms that would otherwise detect and block the malware. Disabling security software grants the cybercriminals unhindered access, leaving sensitive data and critical systems exposed to further compromise.
Gh0st RAT: A Persistent Threat
With system defenses disabled, the campaign proceeds to deploy a variant of Gh0st RAT (Remote Access Trojan). Gh0st RAT is a powerful piece of malware that grants attackers comprehensive remote control over an infected computer. The immediate consequences for victims can include data exfiltration, real-time screen monitoring, arbitrary command execution, and the use of the compromised machine as a staging ground for lateral movement or subsequent attacks.
The group’s strategy of impersonating multiple well-known software names is crucial for expanding its pool of potential victims beyond dedicated AI researchers. Developers, students, and general office workers frequently search for various utilities or cloud services, making them susceptible to the same social engineering tactics. This pattern mirrors other malicious campaigns, such as those involving fake AI repository downloads, where seemingly trustworthy project pages are used to distribute harmful files.
What You Should Do
- Verify Download Sources: Always download software directly from the official vendor’s website or a verified, reputable application store. Avoid downloading software from third-party sites, advertisements, or unsolicited links.
- Exercise Caution with Installers: Treat unexpected MSI files or any installer from an unverified source as highly suspicious. Scrutinize file names, digital signatures, and download URLs.
- Restrict Software Installation: Organizations should implement strict policies limiting who can install software and what types of software can be installed on company devices. Utilize application whitelisting where feasible.
- Monitor for Unusual Activity: Implement robust monitoring for suspicious events, including unsigned or unusual driver installations, unexpected terminations of security services, and installers that launch hidden child processes.
- Keep Systems Updated: Ensure that Windows operating systems and all endpoint security controls (antivirus, EDR) are kept up-to-date with the latest patches and threat definitions.
- Enable Vulnerable Driver Blocklists: Where supported, enable Windows’ vulnerable driver blocklist features to prevent known malicious or exploitable drivers from loading.
- Investigate Security Alerts: Promptly investigate any alerts indicating a sudden loss of protection or unusual system behavior, as this could signal a successful security bypass attempt.
- Educate Users: Conduct regular cybersecurity awareness training for employees, emphasizing the risks of social engineering, phishing, and downloading software from unverified sources.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.