NEWS

BrowserVenom: New Malware Exploits AI Lure

A new malware, BrowserVenom, is exploiting the lure of AI models like DeepSeek-R1 through fake websites and malicious ads. It hijacks browser traffic to steal sensitive user data and credentials.

By
LNGFRM Team
Published June 12, 2025
Web browser displaying a network of interconnected blue nodes. A dark, jagged shape bursts behind the browser, against a blue background with purple lightning bolts.
Illustration by Addison Smith for LNGFRM

The digital frontier of artificial intelligence, promising boundless innovation and efficiency, has rapidly become a new hunting ground for the unscrupulous.

What appears to be the cutting edge of technology can, with a single careless click, transform into an insidious trap, silently siphoning away your digital life.

This stark reality has been laid bare by a recent discovery, revealing a sophisticated cybercriminal operation leveraging the allure of a prominent Chinese AI model, DeepSeek-R1, to unleash a previously unknown malware ominously dubbed “BrowserVenom.”

Its name, BrowserVenom, is chillingly apt, reflecting its core function: to inject a potent poison directly into the arteries of your online existence.

Once entrenched, this malicious software redirects all internet traffic from your browsers through an attacker-controlled server.

Imagine every website you visit, every login you attempt, every piece of information you exchange online, passing through the hands of unseen adversaries.

This gives the crooks an unprecedented level of access, enabling them to steal sensitive data, meticulously monitor browsing activity, and potentially expose plaintext traffic – a digital open book for their nefarious perusal.

The implications are terrifyingly broad.

Credentials for websites, the very keys to your online identity, are at immediate risk.

Session cookies, often overlooked, can be hijacked to bypass login procedures, granting criminals direct access to your active sessions.

Financial account information, sensitive emails, and personal documents – the very bedrock of your digital privacy and security – become fair game.

This treasure trove of data is precisely what scammers seek, either to commit direct digital fraud or to sell on the dark web to other miscreants, fueling a global illicit economy.

Kaspersky, the cybersecurity firm that first unearthed this intricate phishing campaign, warns that BrowserVenom continues to pose a global threat, having already infected “multiple” computers across a diverse range of nations, including Brazil, Cuba, Mexico, India, Nepal, South Africa, and Egypt.

The geographical spread underscores the indiscriminate nature of these attacks, targeting anyone who succumbs to the carefully crafted deception.

The charade begins subtly, preying on the natural curiosity and eagerness surrounding AI advancements.

The cybercriminals meticulously crafted a fake website that eerily resembles the legitimate DeepSeek homepage.

To ensure their digital bait reached the widest possible audience, they resorted to a classic but effective tactic: buying malicious ads from Google.

When unsuspecting users searched for “deepseek r1,” the fake site, identified by the URL deepseek-platform[.]com, often appeared as the top search result, lending it an undeserved air of authenticity.

While Google has since acted, suspending the advertiser’s account prior to the public revelation of this campaign, the incident serves as a stark reminder of the constant cat-and-mouse game between platform security and determined adversaries.

Once a Windows user clicked the deceptive ad and landed on the fake DeepSeek platform, they were prompted with a seemingly innocuous “Try now” button.

Users on other platforms encountered similarly misleading prompts.

Clicking this button didn’t lead to an AI experience, but rather to a CAPTCHA screen – a clever veneer of legitimacy designed to reassure the victim.

Hidden JavaScript on the page performed a critical background check, ensuring the user wasn’t a bot, confirming they had indeed snared a human target worthy of their efforts.

After successfully navigating the fake CAPTCHA, the victim was redirected to a download page, featuring a “Download now” button.

This click initiated the download of the malicious installer, disguised as AI_Launcher_1.21.exe, from a domain subtly different from the initial landing page: r1deepseek-ai[.]com.

The infection process, once the victim executed the downloaded file, was a masterclass in psychological manipulation and technical trickery.

The installer first opened yet another window mimicking a Cloudflare CAPTCHA, further reinforcing the illusion of a legitimate, secure process.

This second verification ensured the victim was still a human, actively engaging with the fake software.

The malware then presented a choice: download and install either Ollama or LM Studio to run DeepSeek.

Crucially, the choice was irrelevant; either option triggered the full BrowserVenom infection.

Upon execution, BrowserVenom first checked for administrator privileges.

If absent, the malware halted, demonstrating a calculated efficiency – why waste resources on a less valuable target?

For those deemed worthy of infection, BrowserVenom proceeded with chilling efficiency.

It installed an attacker-created hardcoded certificate, granting the criminals persistent access to the victim’s system and enabling them to intercept traffic at will.

Simultaneously, it injected a hardcoded proxy server address into all currently installed and running browsers, ensuring every byte of internet traffic flowed through their control.

With these mechanisms in place, the stage was set for their nefarious business: data theft, surveillance, and potential financial ruin for the victim.

Intriguingly, Kaspersky’s analysis of the crooks’ site code revealed comments written in Russian, suggesting a potential linguistic origin for the perpetrators.

However, the security firm has refrained from attributing this sophisticated campaign to any specific cybercrime group or individual, underscoring the shadowy nature of these operations.

This isn’t an isolated incident; it’s a symptom of a far wider, more concerning trend.

The burgeoning interest in artificial intelligence has created a fertile ground for cybercriminals.

They are increasingly leveraging the hype surrounding AI to spread a diverse range of nasty payloads, from credential- and wallet-stealing malware to debilitating ransomware and Windows-borking code.

The tactic remains consistent: create convincing phishing sites with subtly altered domain names, promote them aggressively through malicious ads that dominate search results, and then deliver a digital Trojan horse instead of the promised AI marvel.

The story of BrowserVenom is a potent reminder that in the digital age, vigilance is not merely a recommendation but a necessity.

The promise of groundbreaking technology often walks hand-in-hand with the peril of exploitation.

As AI continues its rapid ascent, users must cultivate a healthy skepticism, scrutinizing every download, every domain name, and every click.

For in the intricate dance between innovation and exploitation, a single misstep can transform a beacon of progress into a digital nightmare.

Author

  • LNGFRM Team

    Frank DiBernardo handles LNGFRM's Foodie and Miscellaneous writing tasks. He's always getting ideas from users, so don't be afraid to send an email to the editor.

Daily Newsletter
Subscribe to our Newletter!
You May Also Like

Mohit Bansal: On Zero-Headcount Security Scaling

Mohit Bansal’s approach to security engineering at Webflow rests on a deceptively simple reframe: treating fixed headcount not as a limitation to work around but as a firm design constraint that shapes every architectural decision, from how vulnerabilities get prioritized to how vendor risk gets automated away. His core discipline is pragmatic sequencing over theoretical perfection—getting 80 percent coverage on five critical risks rather than chasing 100 percent on two—paired with a relentless drive to automate repetitive data-gathering so a fixed team can spend its limited human judgment on the problems that actually require it.

By Mike Malone
Published June 30, 2026
© 2026 LNGFRM. All rights reserved.