DeepSeek - Tool

Threat entity extracted from intelligence sources

Frequency
53
occurrences
First Seen
November 11, 2025
Last Seen
September 9, 2026

DeepSeek is a cybersecurity threat tool/component linked to AI chat data exfiltration and abuse of LLM infrastructure.

Overview

DeepSeek is a cybersecurity threat tool/component linked to AI chat data exfiltration and abuse of LLM infrastructure. It has appeared in malicious Chrome extensions that steal ChatGPT and DeepSeek chats, and is used in threat groups’ toolkits such as the WormGPT variant KawaiiGPT, indicating a focus on harvesting and monetizing AI chat data.

Related Threat Clusters

Recent Intelligence Reports

  • US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models — Securityaffairs.Co · September 9, 2026
  • Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF — Greynoise · September 9, 2026
  • Cyber Agencies Warn AI Companies Against Chinese Firms' Theft — News.Bloomberglaw · September 8, 2026
  • Cyberattacks by Chinese hackers using AI more than double — English.Onlinekhabar · August 25, 2026
  • AI Data Leaks: Every Major Incident & How to Prevent Them — Dexpose · August 25, 2026
  • Chinese hackers exploit DeepSeek to scale overseas cyberattacks amid lax safeguards - CHOSUNBIZ — Biz.Chosun · August 25, 2026
  • DeepSeek, ChatGPT and Claude: How Chinese hackers are using AI in cyberattacks — Firstpost · August 25, 2026
  • China's hackers use DeepSeek for attacks, researchers say — Straitstimes · August 25, 2026

CVSS v3.1 Breakdown