Caution! Analysis of a DeepSeek-imitating phishing website and malicious installation package

Published 2026-05-07 08:00 1458 words 8 min read ... Page views

In-depth analysis of the phishing website web.deepseekem.com and the malicious BrowserVenom Trojan it distributes.
Listen to this article
0:00 / --:--

0x00 Background of the Incident

Recently, while searching for information related to DeepSeek, a highly impersonated phishing website, web.deepseekem.com, was discovered. The design of its pages is extremely similar to that of the official DeepSeek website (deepseek.com), making it almost impossible for ordinary users to distinguish the two visually.

Even more serious is that the website induces users to download a malicious installation package named DeepSeekV20.66-Setup.zip, claiming to be the “DeepSeek desktop client.” Technical analysis has confirmed that this is a typical phishing attack that uses AI to spread malware.

Key conclusions in advance:

  • DeepSeek has never released a desktop client for Windows or Mac.
  • All so-called “desktop installation packages” are actually phishing Trojans.
  • The official services are completely free; there are no paid services available.

0x01 Analysis of the Phishing Website

1.1 Domain Name Impersonation

Comparison ItemOfficial DeepSeekImpersonated Website
Domain Namedeepseek.com or chat.deepseek.comweb.deepseekem.com (with the additional “em”)
Page DesignHighly similar (complete copy)Highly similar
NatureOfficially certified, safe, and reliableImpersonated domain name, high-risk

1.2 Theft of Registration Information

The impersonated website has directly copied the official ICP (Internet Content Protection) registration information:

ItemOfficial InformationImpersonated Website Shows
Registration NumberZhejiang ICP Registration 2023025841-1Exactly the same (stolen)
Hosting CompanyHangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd.Exactly the same (stolen)

Technical Explanation: The ICP registration number is uniquely assigned to a domain name. It is impossible for the registration number of deepseek.com to belong to deepseekem.com. Impersonated websites are usually hosted overseas (e.g., in the United States or Hong Kong) and cannot obtain a legitimate registration in China, so they steal legitimate registration numbers to deceive users.

Verification Method:

  1. Visit the MIIT (Ministry of Industry and Information Technology) ICP registration query website: https://beian.miit.gov.cn
  2. Enter the domain name deepseekem.com to check the registration.
  3. If no record is found, or if the displayed hosting company does not match the actual one, the website is impersonated.

1.3 Known Risks

This impersonated website has been reported by security agencies to be used for spreading the BrowserVenom Trojan, which can steal browser data and hijack online activities. Specific actions include:

  • Stealing passwords and cookies saved in the browser
  • Monitoring and altering user online behavior
  • Forcing redirects to phishing pages
  • Stealing all information entered by users in the background

0x02 Analysis of the Malicious Installation Package

2.1 Basic Information of the Sample

ItemInformation
File NameDeepSeekV20.66-Setup.zip
Hosting Addresskk9win.oss-cn-hongkong.aliyuncs.com
File FormatZIP compressed file
First SubmissionApril 2, 2026
Last AnalysisApril 2, 2026, 11:48

2.2 MicroStep Online Cloud Sandbox Analysis Results

Detection DimensionResultExplanation
MicroStep Intelligence DetectionMaliciousThreat intelligence systems have identified the domain as malicious
Engine Detection Rate2/132 out of 13 detection engines reported the file as malware
Detecting EnginesThreatBookLabs, CheckURLBoth marked as “malware”
Phishing Model DetectionUnknownThe model did not detect it, but intelligence confirms it is malicious

There are historical records of malicious files associated with this domain:

Discovery TimeURLSHA256Detection Rate
March 19, 2026http://kk9win.oss-cn-hongkong.aliyuncs.com29b470e11f5b755e31c141e1cd95597ae689e3ea131cb680b0221cf54e509e332/13
January 9, 2026https://kk9win.oss-cn-hongkong.aliyuncs.com/dow/93b19d038ab57cd9ed8065e97d3fd16f5b4b2614543a3698cfe1bb40530cc6161/13

Analysis Conclusion: The domain kk9win.oss-cn-hongkong.aliyuncs.com has been a source of malicious file distribution since January 2026.

2.4 Analysis of Malware Behavior

Based on sandbox analysis and behavior, the malware has the following capabilities:

Behavior TypeDescriptionSeverity
Information StealingSteals passwords, cookies, and cryptocurrency wallet information from the browserSevere
Browser HijackingMonitors and redirects to phishing pagesSevere
KeyloggingRecords all user input (accounts, passwords, chat content)Severe
Remote Control BackdoorMay allow attackers to remotely control the affected machineSevere

0x03 Emergency Response Measures

3.1 If You Have Downloaded but Not Installed It

  1. Immediately delete the downloaded .zip file.
  2. Empty the recycle bin.
  3. Run antivirus software to scan the downloaded directory.
  4. Check the browser’s download history for any other suspicious files.

3.2 If You Have Unzipped but Not Installed It

  1. Delete the entire unzipped folder.
  2. Run a full-system antivirus scan.
  3. Check if any files have been modified.

3.3 If You Have Installed the Program (highest risk)

Please follow these steps in order:

Step 1: Full-System Antivirus Scan

  • For Windows Defender: Settings → Privacy & Security → Windows Security Center → Virus & Threat Protection → Scan Options → Full Scan
  • Or use a third-party antivirus software (e.g., 360, Qianrong, Tencent PC Manager) for a full system scan.

Step 2: Change Your Passwords

  • Change passwords for all important accounts (email, social media, online banking, DeepSeek, etc.).
  • Enable two-factor authentication (phone verification/code authenticators).
  • Check for any unusual login attempts to your accounts.

Step 3: Check for System Abnormalities

  • Check the task manager for abnormal CPU/memory usage.
  • Check if there are any unfamiliar plugins in the browser or if the homepage has been altered.
  • Look for unexpected pop-ups or changes in network connections.

3.4 Long-Term Security Recommendations

  1. Use DeepSeek only through official channels (see below).
  2. Do not trust download links in search engine advertisements.
  3. Do not download .exe or .zip files from unknown sources.
  4. Keep your antivirus software enabled and up-to-date.

0x04 Official Channels

Please be sure to use only the following official channels. Any claims that require payment to unlock, recharge, or obtain beta access are scams:

Method of UseOfficial Channel
Official Websitedeepseek.com or chat.deepseek.com
Official AppApple App Store, major Android app stores
Developer InformationHangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd.
Official Social AccountsWeChat official account, REDnote, X (Twitter) with the account name DeepSeek

Important Official Statements:

  1. DeepSeek services (web and app) are completely free.
  2. DeepSeek has never released a desktop client for Windows or Mac.
  3. There are no paid services such as “beta access” or “recharge to unlock advanced features.”

0x05 Core Security Guidelines

When encountering suspicious websites or files, remember the following criteria:

Judgment CriterionOfficial CharacteristicsSuspicious Characteristics
Domain Namedeepseek.com or chat.deepseek.comMultiple letters, fewer letters, or replaced letters (e.g., deepsek.com, deepseekem.com)
ClientNo desktop client available; any request for a download package
PricingCompletely freeAny request for payment
Download SourceOfficial app storesThird-party websites, cloud storage, search engine advertisements
Registration InformationCan be verified on the MIIT websiteStolen registration number or no registration

In one sentence: If it’s not deepseek.com, do not enter any information. Any request for a desktop client is likely a scam.


0x06 References and Tools

Tool/PlatformPurposeWebsite
MIIT ICP Registration QueryVerify the authenticity of website registrationshttps://beian.miit.gov.cn
MicroStep Online Cloud SandboxAnalyze malicious files/URLshttps://s.threatbook.com
VirusTotalMulti-engine virus scanninghttps://virustotal.com
Qianxin Threat Intelligence CenterThreat intelligencehttps://ti.qianxin.com
Joe SandboxIn-depth behavior analysishttps://joesandbox.com

0x07 Summary

This article analyzes a phishing attack that takes advantage of DeepSeek’s popularity:

  1. The phishing website web.deepseekem.com deceives users by impersonating the domain name, stealing registration information, and copying the page design.
  2. The malicious file DeepSeekV20.66-Setup.zip has been identified as malware that steals information and hijacks browsers.
  3. The malware has been distributed from the domain kk9win.oss-cn-hongkong.aliyuncs.com since January 2026.
  4. DeepSeek does not offer a desktop client and its services are free; any claims to the contrary are scams.

We hope this article helps people recognize such phishing attempts and prevent financial and information security breaches.


This article is for technical security sharing purposes only and may be reprinted. If you find similar suspicious websites, please report them through platforms like MicroStep Online and warn others to be cautious.

... Page views
© 2026 violet @qiyuan