DeepSeek - Tool

Threat entity extracted from intelligence sources

Frequency
35
occurrences
First Seen
November 11, 2025
Last Seen
July 16, 2026

DeepSeek is a tool tracked across 28 threat clusters and 35 intelligence report mentions on ThreatCluster. First observed November 11, 2025; most recent activity July 16, 2026.

Overview

DeepSeek is a cybersecurity threat tool/component linked to AI chat data exfiltration and abuse of LLM infrastructure. It has appeared in malicious Chrome extensions that steal ChatGPT and DeepSeek chats, and is used in threat groups’ toolkits such as the WormGPT variant KawaiiGPT, indicating a focus on harvesting and monetizing AI chat data.

Related Threat Clusters

  • Boko Haram's Use of AI Chatbots for Terrorism Confirmed by Cambridge Study

    A Cambridge University study reveals Boko Haram has integrated AI tools into its operations, utilizing US and Chinese chatbots for bomb-making, attack planning, and propaganda. The research, based on interviews with 27…

    2 articles · Updated July 15, 2026
  • Critical Zoom Vulnerability Allows Unauthenticated Account Takeover

    Zoom has patched a critical vulnerability (CVE-2026-53412) in its Windows desktop client and VDI software that could allow unauthenticated attackers to take over user accounts via network access. The flaw, rated 9.8 out…

    22 articles · Updated July 16, 2026
  • State-Linked Cyber Threats Intensify Amid AI Advancements

    Recent reports indicate that state-linked hackers are leveraging artificial intelligence to enhance their cyber capabilities, posing significant risks to national utilities and intellectual property. Additionally, a US…

    2 articles · Updated March 11, 2026
  • Anthropic's Claude Code Faces Backlash Over Covert User Tracking of Chinese Users

    Anthropic's AI tool, Claude Code, was found to contain hidden tracking mechanisms targeting Chinese users, raising significant privacy concerns. The covert detection logic, embedded since April 2, 2026, identified users…

    41 articles · Updated July 3, 2026
  • Malicious JetBrains Plugins Exfiltrate AI API Keys from Developers

    A coordinated malware campaign has been uncovered involving at least 15 malicious plugins on the JetBrains Marketplace, designed to steal AI API keys from developers. These plugins, masquerading as AI coding assistants,…

    7 articles · Updated June 16, 2026
  • Critical RCE Vulnerability Discovered in SGLang Framework via GGUF Models

    A remote code execution vulnerability has been identified in the SGLang framework, specifically affecting the reranking endpoint (/v1/rerank) and tracked as CVE-2026-5760. This flaw allows attackers to exploit…

    7 articles · Updated April 21, 2026
  • AI-Enhanced Credential Harvesting Operation Exposed

    A threat actor has integrated Anthropic's Claude Code AI into a large-scale credential harvesting operation named Bissa scanner. This operation has successfully exploited over 900 targets since September 2025, utilizing…

    3 articles · Updated April 23, 2026
  • Malicious Browser Add-Ons Exploit AI Platform Users

    Malicious browser add-ons are targeting users of popular AI platforms such as ChatGPT, Claude, Copilot, Gemini, and DeepSeek. These extensions masquerade as helpful tools but are actually harvesting personal data and…

    2 articles · Updated June 5, 2026
  • 282 iOS Apps Expose LLM API Credentials via Network Traffic

    A study by Wake Forest University revealed that 282 out of 444 analyzed iOS applications with AI features are leaking Large Language Model (LLM) API credentials through network traffic. This vulnerability affects apps…

    6 articles · Updated June 22, 2026
  • Ransomware Fuels Surge in Global Cyberattacks

    As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…

    1551 articles · Updated February 12, 2026

Recent Intelligence Reports

  • Zoom Fixes CVE-2026-53412, a Critical Account Takeover Bug — Securityaffairs · July 16, 2026
  • Boko Haram exploited US and Chinese AI chatbots for attacks, Cambridge study finds — Scmp · July 15, 2026
  • Boko Haram Built AI Units for Explosives Design, Attack Planning as ISIS Taught Jailbreaks — Techtimes · July 12, 2026
  • Alibaba bans Claude Code over hidden Chinese user tracking — Thenextweb · July 3, 2026
  • AI Agent Executes End-to-End Ransomware Attack | Let's Data Science — Letsdatascience · July 2, 2026
  • Researchers find hundreds of iOS apps leaking AI credentials - Let's Data Science — Letsdatascience · June 22, 2026
  • Fifteen JetBrains Marketplace Plugins Found Stealing API Keys — Infosecurity-Magazine · June 17, 2026
  • Malicious JetBrains Marketplace plugins steal AI API keys from developers — Bleepingcomputer · June 16, 2026

CVSS v3.1 Breakdown