Tuesday, March 18, 2025
HomeAIHackers Exploit DeepSeek & Qwen AI Models for Malware Development

Hackers Exploit DeepSeek & Qwen AI Models for Malware Development

Published on

SIEM as a Service

Follow Us on Google News

Check Point Research (CPR) has revealed that cybercriminals are increasingly leveraging the newly launched AI models, DeepSeek and Qwen, to create malicious content.

These models, which lack robust anti-abuse provisions, have quickly become a preferred choice for threat actors over more regulated platforms like ChatGPT.

The exploitation of these tools highlights a concerning shift in the cyber threat landscape, where even low-skilled attackers can harness advanced AI capabilities to execute sophisticated attacks.

Unlike ChatGPT, which has implemented stringent anti-abuse mechanisms over the years, DeepSeek and Qwen appear to offer minimal resistance to misuse.

Threat actors are actively sharing methods to manipulate these models through techniques known as “jailbreaking,” enabling them to bypass restrictions and generate uncensored or harmful content.

Jailbreaking techniques such as the “Do Anything Now” and “Plane Crash Survivors” methods are being widely circulated among cybercriminal communities, further facilitating the misuse of these AI systems.

Qwen AI Models
Jailbreaking Prompt

Real-World Exploits

The misuse of DeepSeek and Qwen has already led to alarming real-world consequences.

For instance, CPR has identified cases where these models were used to develop infostealers malware designed to extract sensitive information from unsuspecting users.

Additionally, cybercriminals have employed DeepSeek to bypass banking anti-fraud protections, potentially enabling large-scale financial theft.

Another troubling trend involves the use of these AI tools in mass spam distribution campaigns.

By combining ChatGPT with DeepSeek and Qwen, attackers are optimizing scripts for spam operations, enhancing their efficiency and reach.

This multi-platform approach underscores the growing sophistication of cyberattacks driven by generative AI technologies.

The Rising Threat of Unregulated AI Models

The rapid adoption of DeepSeek and Qwen by malicious actors underscores the urgent need for stronger safeguards in emerging AI technologies.

As uncensored versions of these models begin to surface on online repositories similar to what has been observed with ChatGPT, the risks associated with their misuse are expected to escalate further.

These tools are not only empowering seasoned hackers but also enabling low-skilled individuals to execute complex attacks without extensive technical expertise.

Check Point Research warns that the emergence of these unregulated AI models represents a significant challenge for cybersecurity professionals.

Without proactive measures to address vulnerabilities and prevent misuse, organizations risk exposure to malware development, financial fraud, and other cyber threats fueled by generative AI advancements.

As the race to develop next-generation AI tools continues, prioritizing security will be critical in mitigating the risks associated with their exploitation.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

MirrorGuard: Adaptive Defense Mechanism Against Jailbreak Attacks for Secure Deployments

A novel defense strategy, MirrorGuard, has been proposed to enhance the security of large...

New ClearFake Variant Uses Fake reCAPTCHA to Deploy Malicious PowerShell Code

A recent variant of the ClearFake malware framework has been identified, leveraging fake reCAPTCHA...

New BitM Attack Enables Hackers to Hijack User Sessions in Seconds

A recent threat intelligence report highlights the emergence of a sophisticated cyberattack technique known...

Hackers Exploit Hard Disk Image Files to Deploy VenomRAT

In a recent cybersecurity threat, hackers have been using virtual hard disk image files...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

MirrorGuard: Adaptive Defense Mechanism Against Jailbreak Attacks for Secure Deployments

A novel defense strategy, MirrorGuard, has been proposed to enhance the security of large...

New ClearFake Variant Uses Fake reCAPTCHA to Deploy Malicious PowerShell Code

A recent variant of the ClearFake malware framework has been identified, leveraging fake reCAPTCHA...

New BitM Attack Enables Hackers to Hijack User Sessions in Seconds

A recent threat intelligence report highlights the emergence of a sophisticated cyberattack technique known...