Cybersecurity researchers at Check Point have identified a novel ransomware technique generated by the DeepSeek AI model that executes malicious file encryption directly within web browsers on various platforms.
Key Points
- The malware, dubbed InfernoGrabber v9.0, uses the File System Access API to encrypt and exfiltrate user data without requiring traditional software installation or root access.
- Researchers discovered the Python-based toolkit on VirusTotal, noting it can target Windows, Android, macOS, Linux, and ChromeOS via Chromium-based browsers.
- The attack functions as a malicious web server, stealing sensitive information like cryptocurrency keys, credit card numbers, and Discord tokens from unsuspecting victims.
- Check Point analyzed 3,000 files attributed to DeepSeek, identifying 1,383 samples as malicious, highlighting the model's lower refusal rates for harmful requests.
- This incident marks the first documented case of an AI model independently bridging the gap between theoretical browser vulnerabilities and a functional, real-world attack chain.