{"id":7227,"date":"2025-02-06T14:54:57","date_gmt":"2025-02-06T20:54:57","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/deepseek-phishing-sites-pursue-user-data-crypto-wallets"},"modified":"2025-02-06T14:54:57","modified_gmt":"2025-02-06T20:54:57","slug":"deepseek-phishing-sites-pursue-user-data-crypto-wallets","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/02\/06\/deepseek-phishing-sites-pursue-user-data-crypto-wallets\/","title":{"rendered":"DeepSeek Phishing Sites Pursue User Data, Crypto Wallets"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt6ba00013f7ce94a5\/67a511492737975a3d060ba3\/deepseek_mundissima_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">More than two weeks after China&#8217;s DeepSeek garnered worldwide attention with its low-cost AI model, threat actors have been busy capitalizing on the news by setting up phishing sites impersonating the company.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The fraudulent sites aim to deceive users into downloading malicious software or providing credentials and other sensitive information. Researchers at Israel-based Memcyco spotted at least 16 such sites actively impersonating DeepSeek earlier this week and believe the activity represents a coordinated attack campaign among threat actors.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Coordinated Campaign?\">Coordinated Campaign?<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Memcyco observed clusters of fake domains registered in waves, often adjusting their content and branding dynamically and in real time, based on how DeepSeek&#8217;s website was being perceived and positioned in the market,&#8221; says Israel Mazin, CEO and co-founder of Memcyco. &#8220;Some sites even changed their attack methods based on these trends to cater to what would be most effective.&#8221; In some cases, the threat actors displayed remarkable agility by shifting their infrastructure to new locations and configurations to dodge takedown attempts, he says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dozens of phishing sites have popped up since DeepSeek released its free R1 AI chatbot on Jan. 20. Although many of these sites have been taken down, slow response times from some hosting providers, domain registrars, and other intermediaries continue to give phishing operators a window of opportunity to target users interested in exploring DeepSeek with fake websites.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Users that engage with these sites risk identity theft, financial fraud, and malware infection, Mazin says. Some sites even intercept login credentials in real-time, enabling account takeovers. Others distribute malware that allows remote access to users&#8217; devices, putting personal and corporate data at risk. &#8220;These attacks are especially dangerous when new, exciting, and hyped-up tools are launched, such as DeepSeek, and users are not yet familiar with the website or platform,&#8221; he adds.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Others have reported on the threat as well. In a blog post last week, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/cyble.com\/blog\/deepseeks-growing-influence-surge-frauds-phishing-attacks\/\">Cyble<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, for instance, said its researchers had spotted DeepSeek lookalike domains designed to trick users into believing they had landed on the real site. Some of the sites had links to cryptocurrency scams and others to fraudulent investment scams like one touting a nonexistent DeepSeek pre-IPO sale. The DeepSeek-linked cryptocurrency scam site attempted to lure site visitors into <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/qr-code-quishing-attacks-execs-email-security\">scanning a QR code<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that essentially opened the way for the threat actor to empty their crypto wallets. Another site that Cyble inspected attempted to lure unsuspecting users into purchasing a fake DeepSeekAI Agent&nbsp;crypto token.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;As DeepSeek continues to gain global recognition, cybercriminals are capitalizing on its popularity to launch phishing campaigns, fake investment scams, and fraudulent cryptocurrency schemes,&#8221; Cyble noted.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Phishing Isn't the Only Threat\">Phishing Isn&#8217;t the Only Threat<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Fraudulent websites are not the only concern. Innovative threat actors have found other ways to take advantage of the huge interest around DeepSeek. Researchers from Positive Technologies recently spotted <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/application-security\/ai-malware-deepseek-packages-pypi\">two malicious packages<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> labeled &#8220;deepseekai&#8221; and &#8220;deepseeek&#8221; on the popular PyPI Python package repository. The packages were targeted at developers and organizations seeking to integrate DeepSeek into their systems and gave its authors a way to steal information from environments where they had been downloaded.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Many of the phishing sites that Memcyco observed appeared to fit the pattern of phishing-as-a-service (PhaaS) operators that sell impersonation &#8220;phish kits&#8221; to fraudsters, Mazin notes. &#8220;This could include organized cybercriminal groups,&nbsp;state-backed hackers, or even immature phishers, all with financial or espionage motives.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The surge in malicious activity surrounding DeekSeek is typical for major news events. It is a reminder of the need for users to be cautious when approaching new, popular hyped-up services. That means extra vigilance for strange URLs with misspelled words or unprofessional website designs, Mazin advises. &#8220;Domain registrars and social media platforms must be proactive in monitoring when new domains and profiles are being registered or created,&#8221; he says. &#8220;Businesses and organizations should improve scam detection [and] takedowns and deploy real-time digital impersonation protection capabilities to safeguard their users.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/deepseek-phishing-sites-pursue-user-data-crypto-wallets\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>More than two weeks after China&#8217;s DeepSeek garnered worldwide attention<\/p>\n","protected":false},"author":12,"featured_media":7228,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-7227","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/deepseek-phishing-sites-pursue-user-data-crypto-wallets.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7227","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=7227"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7227\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/7228"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=7227"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=7227"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=7227"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}