Massive DDoS Attack Hits DeepSeek AI, Command Activity Surges 100x
Massive DDoS Attack Hits DeepSeek AI, Command Activity Surges 100x
Cybersecurity Insights

By Patricia A. Pramono • Studio 1080, Published on February 10, 2025

SHARE THIS ARTICLE

Imagine an AI model that not only rivals OpenAI’s ChatGPT and Google’s Gemini AI but does so at a fraction of the cost, that’s DeepSeek AI. Born out of China’s rapidly growing AI industry, this platform has stunned tech enthusiasts, researchers, and even Wall Street with its advanced reasoning capabilities, multimodal understanding, and efficiency, all while operating on a significantly smaller budget compared to its competitors.

DeepSeek AI is a game changer for AI chatbots. Within weeks of launching, it became the most-downloaded free app on Apple’s App Store, dethroning ChatGPT. Tech analysts marveled at its ability to perform at the same level as some of the biggest AI models on the market. Some even started questioning whether DeepSeek’s rise signaled a shift in the AI power dynamic and whether this was the moment when China’s AI industry officially caught up.

But with great success comes great scrutiny. The more disruptive DeepSeek AI became, the more attention it attracted, not just from users and investors but also from cyber attackers.

And in January 2025, that attention turned into a large-scale cyberattack that sent shockwaves through the AI world.

The Cyberattack That Crippled DeepSeek AI

Early January 2025: The First Signs

Shortly after DeepSeek AI soared to the top of rankings, the first wave of cyberattacks quietly began. Global Times and Ecns.cn have reported that according to cybersecurity analysts at XLab (a Chinese cybersecurity firm), the initial attacks took the form of SSDP (Simple Service Discovery Protocol) and NTP (Network Time Protocol) reflection amplification attacks. These are classic DDoS (Distributed Denial-of-Service) techniques, where attackers manipulate internet protocols to flood a target with fake traffic, overwhelming its servers and slowing down services.

Also read: A Series of DDoS Attack Affecting Japanese Corporations

At this stage, the attacks were disruptive but manageable. DeepSeek AI’s security team was able to mitigate most of the damage and keep services operational. However, this was just the beginning.

Mid-January 2025: The Attacks Get Smarter

By mid-January, the attackers changed tactics. XLab observed a shift from basic reflection amplification methods to more complex HTTP proxy attacks. Unlike the earlier attacks, which focused on overwhelming the network, these new attacks targeted the application layer, making them much harder to detect and defend against.

January 28-29, 2025: A 100x Surge in Attack Commands

Then, on the night of January 28, everything escalated.

Attack commands spiked by more than 100 times compared to the earlier waves, signaling a massive escalation. According to XLab, this surge was driven by the involvement of botnets (specifically, two Mirai-variant botnets known as HailBot and RapperBot.)

Botnets are networks of infected devices—often compromised computers, routers, or IoT devices—that cybercriminals control remotely to execute large-scale attacks. The entry of botnets into the attack meant that DeepSeek AI was no longer dealing with just a wave of cyberattacks—it was now facing a coordinated and relentless assault.

  • Wave 1: 1:00 AM – HailBot and RapperBot launched the first major strike, utilizing 118 C2 (Command and Control) ports across 16 different servers

  • Wave 2: 2:00 AM – A second wave followed almost immediately, intensifying the assault on DeepSeek’s infrastructure

January 30, 2025: The Aftermath

As the attacks continued, DeepSeek then released an urgent announcement, stating that its platform had been subjected to large-scale malicious attacks and that it would need to implement temporary restrictions.

The impact?

  • DeepSeek had to limit new user registrations to Chinese mobile numbers (+86) only, effectively restricting global access to international users

  • The service faced major slowdowns and accessibility issues

  • The attack sparked global concerns over the security of AI platforms, especially open-source AI models that might lack enterprise-level cybersecurity defenses

Reports from Forbes, CNBC, and the BBC highlighted how the attack on DeepSeek raised serious questions about AI security. If an open-source AI model with cutting-edge capabilities could be taken down by cybercriminals, what did this mean for the future of AI-driven platforms?

Security experts noted that the attackers were likely professionals, possibly engaging in cyber warfare, corporate sabotage, or financially motivated hacking. DeepSeek’s rapid rise had made it a target, and now, the company was at the center of one of the biggest AI cybersecurity incidents.

What Does This Mean for AI Security?

This attack highlights a critical issue in today’s rapidly evolving AI era: security often lags behind innovation.

AI startups, especially those that scale as fast as DeepSeek, face enormous cybersecurity challenges. The moment a company gains global attention, it also becomes a prime target for cybercriminals, hacktivists, and even competitors.

This isn’t just a DeepSeek problem but an industry-wide issue:

  • Open-source AI models, while great for accessibility, can be vulnerable to exploitation

  • AI platforms with API access and cloud-based operations are susceptible to DDoS attacks, data breaches, and model manipulation

  • As AI continues to influence industries from finance to healthcare, securing these platforms is essential

Don’t wait until a cyberattack disrupts your operations. Whether you’re an AI-driven company or a business handling sensitive data, powerful cybersecurity is non-negotiable. Is your company prepared for such threats? Contact our team at Cisometric to learn how our Security Operations Center (SOC) can help you stay ahead of cyber risks.

Also read: Staying Ahead of Threats with 24/7 SOC Proactive Monitoring

 

Reference: 

DeepSeek: The Chinese AI app that has the world talking

DeepSeek hit with large-scale cyberattack, says it’s limiting registrations

Global Times: Cyberattacks against DeepSeek escalate with botnets joining, command surging over 100 times: lab

You may like this...

Cybersecurity Insights
Understanding Malware Threats

Understanding Malware Threats

With digital transformation accelerating rapidly, understanding malware threats is crucial for both individuals and organizations. Malware, short for malicious software, refers to any software intentionally designed to cause damage to a computer, server, client, or computer network.

Read More
Industry Updates
PDN Data Breach and What Does it Mean For Us?

PDN Data Breach and What Does it Mean For Us?

In June 2024, we were rocked by a massive cyber attack that compromised our very own Pusat Data Nasional / National Data Center (PDN)

Read More
Cybersecurity Insights
Ransomware in the Transport Sector: Proactive Cybersecurity Needed

Ransomware in the Transport Sector: Proactive Cybersecurity Needed

In January 2024, one of Indonesia's largest transportation companies became the target of a sophisticated ransomware attack. For an entire week, the company remained unaware that its systems had been breached, giving hackers ample time to infiltrate, exfiltrate, and potentially sell sensitive data.

Read More
Cybersecurity Insights
Can YouTube Videos Secretly Infect Your Device?

Can YouTube Videos Secretly Infect Your Device?

This topic is often under the radar, with many people unaware of the risks they face while enjoying their favorite videos. YouTube, the world’s largest video-sharing platform, is full of engaging, educational, and entertaining content that keeps us coming back day after day. We trust it, and because of that trust, we let our guard down. After all, it’s just YouTube – how bad could it be?

Read More
Cybersecurity Insights
Stop Making These Common Password Mistakes

Stop Making These Common Password Mistakes

The harsh reality is that cyber threats are evolving every day, and what might have seemed secure a year ago could now be a ticking time bomb. A single compromised password can open the doorways to identity theft, financial loss, or even permanent loss of access to your accounts.

Read More

Search Article by Category