Some AI chatbots can be operated directly on your PC. However, you should proceed with caution: a newly identified Windows malware takes advantage of interest in DeepSeek’s AI models to compromise computers. Kaspersky, an antivirus provider, reports that this attack deploys the “BrowserVenom” malware, which can covertly monitor and manipulate user internet activity.
Hackers are using Google ads to promote a fake version of DeepSeek’s “R1” model, misleading users into clicking on links. Many new users of generative AI may not recognize the legitimate websites hosting the R1 model.
(Credit: Kaspersky)
When users clicked these ads, they were taken to a deceptive DeepSeek site at “https[:]//deepseek-platform[.]com,” where a button prompted them to download the R1 model. The intention was to trick users into downloading a harmful file labeled “AI_Launcher_1.21.exe.”
Kaspersky investigated the source code of both the phishing and distribution sites, finding comments in Russian, indicating they were likely created by Russian-speaking cybercriminals.
(Credit: Kaspersky)
Executing the malicious .exe file presented a fake installation screen for R1. However, in reality, it installed the BrowserVenom malware. This harmful software altered the PC’s browsers to send traffic through an attacker-controlled proxy, allowing cybercriminals to intercept sensitive information and monitor the user’s online activity, as detailed by Kaspersky.
Recommended by Our Editors
Fortunately, the malicious domain linked to this attack has been taken down. Nevertheless, the malware, which is capable of bypassing most antivirus software, has affected certain users. Kaspersky has identified infections in countries including Brazil, Cuba, Mexico, India, Nepal, South Africa, and Egypt.
This situation serves as a crucial reminder to always verify that you are using the official website or platform of an AI company before downloading. Additionally, running open-source AI applications like R1 on a PC involves several steps; it’s not just a straightforward installation.

Get Our Best Stories!
Stay Safe With the Latest Security News and Updates
By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up!
Your subscription has been confirmed. Watch your inbox!
About Michael Kan
Senior Reporter
