Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
GhostJacking Attack Hijacks AI Agents to Run Malicious Code on Developer Machines
August 11, 2026
Horizon3.ai Secures $20M to Boost Partner-Led Growth and Ecosystem
August 11, 2026
Chinese Hackers Use Fake DeepSeek Page to Deliver Malware
August 11, 2026
Home/Threats/Chinese Hackers Use Fake DeepSeek Page to Deliver Malware
Threats

Chinese Hackers Use Fake DeepSeek Page to Deliver Malware

Key Takeaways A Chinese-speaking cybercrime group is distributing remote access malware through deceptive software download pages. The attackers impersonate legitimate AI tools like DeepSeek, Quark...

Jennifer sherman
Jennifer sherman
August 11, 2026 4 Min Read
2 0

Key Takeaways

  • A Chinese-speaking cybercrime group is distributing remote access malware through deceptive software download pages.
  • The attackers impersonate legitimate AI tools like DeepSeek, Quark Cloud, and Pony Activator to trick Windows users into downloading malicious installers.
  • The infection chain leverages a vulnerable, signed driver (Adlice TrueSight v2.0.2) to disable over 200 security products before deploying the Gh0st RAT.
  • The campaign highlights the ongoing threat of supply chain attacks and the exploitation of trust in widely used software and AI platforms.
  • Users and organizations must verify download sources, restrict software installations, and monitor for unusual system activities, especially driver loads and security service terminations.

Chinese Hackers Exploit AI Enthusiasm with Fake DeepSeek Pages to Deliver Malware

A sophisticated campaign orchestrated by a Chinese-speaking cybercrime group is leveraging fraudulent software download portals, mimicking popular artificial intelligence (AI) tools, to infect Windows users with potent remote access malware. The operation capitalizes on the growing interest in AI, presenting seemingly legitimate installers for applications such as DeepSeek, Quark Cloud, and Pony Activator, only to deliver a multi-stage malicious payload.

Table Of Content

  • Key Takeaways
  • Chinese Hackers Exploit AI Enthusiasm with Fake DeepSeek Pages to Deliver Malware
  • The Deceptive Infection Chain
  • Gh0st RAT: A Persistent Threat
  • What You Should Do

The security researchers at Zscaler ThreatLabz said in a report that the threat actors utilized AI-generated content to enhance the authenticity of their deceptive download pages. This tactic allows the attackers to create convincing lures, turning genuine user interest in AI software into an unwitting conduit for malware distribution. The campaign underscores a critical and persistent risk: a professional-looking website or a familiar logo does not inherently validate the safety of a software download, particularly when sourced from advertisements, search engine results, or unexpected links.

The Deceptive Infection Chain

The initial stage of the attack involves a Windows Installer (MSI) package crafted using the WiX toolkit. Unlike standard software installers, this particular MSI incorporates a custom action designed to execute malicious code rather than simply installing an application. This subtle engineering helps the file blend in with legitimate setup software while covertly preparing the target system for subsequent malicious activities.

Upon execution, the installer decrypts additional payloads directly into memory, a technique that significantly reduces the forensic footprint left on disk. This stealthy approach complicates detection and analysis, potentially delaying security alerts and investigations. Zscaler ThreatLabz researchers further noted that similar lures have been observed in malvertising campaigns targeting DeepSeek users, directing them to harmful downloads via lookalike websites. pic.twitter.com/N51nl6qEDw

As detailed by Zscaler ThreatLabz on August 10, 2026, following the initial compromise, the attackers exploit a known vulnerability within a digitally signed driver: Adlice TrueSight version 2.0.2. This vulnerable driver is then used to forcibly terminate over 200 different security products installed on the victim’s system. Operating deep within the Windows kernel, drivers possess elevated privileges, allowing attackers to effectively neutralize endpoint protection mechanisms that would otherwise detect and block the malware. Disabling security software grants the cybercriminals unhindered access, leaving sensitive data and critical systems exposed to further compromise.

Gh0st RAT: A Persistent Threat

With system defenses disabled, the campaign proceeds to deploy a variant of Gh0st RAT (Remote Access Trojan). Gh0st RAT is a powerful piece of malware that grants attackers comprehensive remote control over an infected computer. The immediate consequences for victims can include data exfiltration, real-time screen monitoring, arbitrary command execution, and the use of the compromised machine as a staging ground for lateral movement or subsequent attacks.

The group’s strategy of impersonating multiple well-known software names is crucial for expanding its pool of potential victims beyond dedicated AI researchers. Developers, students, and general office workers frequently search for various utilities or cloud services, making them susceptible to the same social engineering tactics. This pattern mirrors other malicious campaigns, such as those involving fake AI repository downloads, where seemingly trustworthy project pages are used to distribute harmful files.

What You Should Do

  • Verify Download Sources: Always download software directly from the official vendor’s website or a verified, reputable application store. Avoid downloading software from third-party sites, advertisements, or unsolicited links.
  • Exercise Caution with Installers: Treat unexpected MSI files or any installer from an unverified source as highly suspicious. Scrutinize file names, digital signatures, and download URLs.
  • Restrict Software Installation: Organizations should implement strict policies limiting who can install software and what types of software can be installed on company devices. Utilize application whitelisting where feasible.
  • Monitor for Unusual Activity: Implement robust monitoring for suspicious events, including unsigned or unusual driver installations, unexpected terminations of security services, and installers that launch hidden child processes.
  • Keep Systems Updated: Ensure that Windows operating systems and all endpoint security controls (antivirus, EDR) are kept up-to-date with the latest patches and threat definitions.
  • Enable Vulnerable Driver Blocklists: Where supported, enable Windows’ vulnerable driver blocklist features to prevent known malicious or exploitable drivers from loading.
  • Investigate Security Alerts: Promptly investigate any alerts indicating a sudden loss of protection or unusual system behavior, as this could signal a successful security bypass attempt.
  • Educate Users: Conduct regular cybersecurity awareness training for employees, emphasizing the risks of social engineering, phishing, and downloading software from unverified sources.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical LiteLLM Supply Chain Flaw Exposes 2,500 Companies, 434,000 CI/CD Pipelines

Next Post

Horizon3.ai Secures $20M to Boost Partner-Led Growth and Ecosystem

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical VMware vCenter CVE-2023-34048 Under Active Exploitation
August 11, 2026
Critical ClamAV Vulnerabilities Let Attackers Trigger DoS
August 11, 2026
Phishing Attack Uses SSL/TLS Certificates to Target WhatsApp Users
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us