0x00 Background of the Incident
Recently, while searching for information related to DeepSeek, a highly impersonated phishing website, web.deepseekem.com, was discovered. The design of its pages is extremely similar to that of the official DeepSeek website (deepseek.com), making it almost impossible for ordinary users to distinguish the two visually.
Even more serious is that the website induces users to download a malicious installation package named DeepSeekV20.66-Setup.zip, claiming to be the “DeepSeek desktop client.” Technical analysis has confirmed that this is a typical phishing attack that uses AI to spread malware.
Key conclusions in advance:
- DeepSeek has never released a desktop client for Windows or Mac.
- All so-called “desktop installation packages” are actually phishing Trojans.
- The official services are completely free; there are no paid services available.
0x01 Analysis of the Phishing Website
1.1 Domain Name Impersonation
| Comparison Item | Official DeepSeek | Impersonated Website |
|---|---|---|
| Domain Name | deepseek.com or chat.deepseek.com | web.deepseekem.com (with the additional “em”) |
| Page Design | Highly similar (complete copy) | Highly similar |
| Nature | Officially certified, safe, and reliable | Impersonated domain name, high-risk |
1.2 Theft of Registration Information
The impersonated website has directly copied the official ICP (Internet Content Protection) registration information:
| Item | Official Information | Impersonated Website Shows |
|---|---|---|
| Registration Number | Zhejiang ICP Registration 2023025841-1 | Exactly the same (stolen) |
| Hosting Company | Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd. | Exactly the same (stolen) |
Technical Explanation: The ICP registration number is uniquely assigned to a domain name. It is impossible for the registration number of deepseek.com to belong to deepseekem.com. Impersonated websites are usually hosted overseas (e.g., in the United States or Hong Kong) and cannot obtain a legitimate registration in China, so they steal legitimate registration numbers to deceive users.
Verification Method:
- Visit the MIIT (Ministry of Industry and Information Technology) ICP registration query website:
https://beian.miit.gov.cn - Enter the domain name
deepseekem.comto check the registration. - If no record is found, or if the displayed hosting company does not match the actual one, the website is impersonated.
1.3 Known Risks
This impersonated website has been reported by security agencies to be used for spreading the BrowserVenom Trojan, which can steal browser data and hijack online activities. Specific actions include:
- Stealing passwords and cookies saved in the browser
- Monitoring and altering user online behavior
- Forcing redirects to phishing pages
- Stealing all information entered by users in the background
0x02 Analysis of the Malicious Installation Package
2.1 Basic Information of the Sample
| Item | Information |
|---|---|
| File Name | DeepSeekV20.66-Setup.zip |
| Hosting Address | kk9win.oss-cn-hongkong.aliyuncs.com |
| File Format | ZIP compressed file |
| First Submission | April 2, 2026 |
| Last Analysis | April 2, 2026, 11:48 |
2.2 MicroStep Online Cloud Sandbox Analysis Results
| Detection Dimension | Result | Explanation |
|---|---|---|
| MicroStep Intelligence Detection | Malicious | Threat intelligence systems have identified the domain as malicious |
| Engine Detection Rate | 2/13 | 2 out of 13 detection engines reported the file as malware |
| Detecting Engines | ThreatBookLabs, CheckURL | Both marked as “malware” |
| Phishing Model Detection | Unknown | The model did not detect it, but intelligence confirms it is malicious |
2.3 Records of Related Malicious Files
There are historical records of malicious files associated with this domain:
| Discovery Time | URL | SHA256 | Detection Rate |
|---|---|---|---|
| March 19, 2026 | http://kk9win.oss-cn-hongkong.aliyuncs.com | 29b470e11f5b755e31c141e1cd95597ae689e3ea131cb680b0221cf54e509e33 | 2/13 |
| January 9, 2026 | https://kk9win.oss-cn-hongkong.aliyuncs.com/dow/ | 93b19d038ab57cd9ed8065e97d3fd16f5b4b2614543a3698cfe1bb40530cc616 | 1/13 |
Analysis Conclusion: The domain kk9win.oss-cn-hongkong.aliyuncs.com has been a source of malicious file distribution since January 2026.
2.4 Analysis of Malware Behavior
Based on sandbox analysis and behavior, the malware has the following capabilities:
| Behavior Type | Description | Severity |
|---|---|---|
| Information Stealing | Steals passwords, cookies, and cryptocurrency wallet information from the browser | Severe |
| Browser Hijacking | Monitors and redirects to phishing pages | Severe |
| Keylogging | Records all user input (accounts, passwords, chat content) | Severe |
| Remote Control Backdoor | May allow attackers to remotely control the affected machine | Severe |
0x03 Emergency Response Measures
3.1 If You Have Downloaded but Not Installed It
- Immediately delete the downloaded
.zipfile. - Empty the recycle bin.
- Run antivirus software to scan the downloaded directory.
- Check the browser’s download history for any other suspicious files.
3.2 If You Have Unzipped but Not Installed It
- Delete the entire unzipped folder.
- Run a full-system antivirus scan.
- Check if any files have been modified.
3.3 If You Have Installed the Program (highest risk)
Please follow these steps in order:
Step 1: Full-System Antivirus Scan
- For Windows Defender: Settings → Privacy & Security → Windows Security Center → Virus & Threat Protection → Scan Options → Full Scan
- Or use a third-party antivirus software (e.g., 360, Qianrong, Tencent PC Manager) for a full system scan.
Step 2: Change Your Passwords
- Change passwords for all important accounts (email, social media, online banking, DeepSeek, etc.).
- Enable two-factor authentication (phone verification/code authenticators).
- Check for any unusual login attempts to your accounts.
Step 3: Check for System Abnormalities
- Check the task manager for abnormal CPU/memory usage.
- Check if there are any unfamiliar plugins in the browser or if the homepage has been altered.
- Look for unexpected pop-ups or changes in network connections.
3.4 Long-Term Security Recommendations
- Use DeepSeek only through official channels (see below).
- Do not trust download links in search engine advertisements.
- Do not download
.exeor.zipfiles from unknown sources. - Keep your antivirus software enabled and up-to-date.
0x04 Official Channels
Please be sure to use only the following official channels. Any claims that require payment to unlock, recharge, or obtain beta access are scams:
| Method of Use | Official Channel |
|---|---|
| Official Website | deepseek.com or chat.deepseek.com |
| Official App | Apple App Store, major Android app stores |
| Developer Information | Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co., Ltd. |
| Official Social Accounts | WeChat official account, REDnote, X (Twitter) with the account name DeepSeek |
Important Official Statements:
- DeepSeek services (web and app) are completely free.
- DeepSeek has never released a desktop client for Windows or Mac.
- There are no paid services such as “beta access” or “recharge to unlock advanced features.”
0x05 Core Security Guidelines
When encountering suspicious websites or files, remember the following criteria:
| Judgment Criterion | Official Characteristics | Suspicious Characteristics |
|---|---|---|
| Domain Name | deepseek.com or chat.deepseek.com | Multiple letters, fewer letters, or replaced letters (e.g., deepsek.com, deepseekem.com) |
| Client | No desktop client available; any request for a download package | |
| Pricing | Completely free | Any request for payment |
| Download Source | Official app stores | Third-party websites, cloud storage, search engine advertisements |
| Registration Information | Can be verified on the MIIT website | Stolen registration number or no registration |
In one sentence: If it’s not deepseek.com, do not enter any information. Any request for a desktop client is likely a scam.
0x06 References and Tools
| Tool/Platform | Purpose | Website |
|---|---|---|
| MIIT ICP Registration Query | Verify the authenticity of website registrations | https://beian.miit.gov.cn |
| MicroStep Online Cloud Sandbox | Analyze malicious files/URLs | https://s.threatbook.com |
| VirusTotal | Multi-engine virus scanning | https://virustotal.com |
| Qianxin Threat Intelligence Center | Threat intelligence | https://ti.qianxin.com |
| Joe Sandbox | In-depth behavior analysis | https://joesandbox.com |
0x07 Summary
This article analyzes a phishing attack that takes advantage of DeepSeek’s popularity:
- The phishing website
web.deepseekem.comdeceives users by impersonating the domain name, stealing registration information, and copying the page design. - The malicious file
DeepSeekV20.66-Setup.ziphas been identified as malware that steals information and hijacks browsers. - The malware has been distributed from the domain
kk9win.oss-cn-hongkong.aliyuncs.comsince January 2026. - DeepSeek does not offer a desktop client and its services are free; any claims to the contrary are scams.
We hope this article helps people recognize such phishing attempts and prevent financial and information security breaches.
This article is for technical security sharing purposes only and may be reprinted. If you find similar suspicious websites, please report them through platforms like MicroStep Online and warn others to be cautious.