1 Static Analysis of The DeepSeek Android App
harrisdymock53 edited this page 2025-02-10 13:20:36 +07:00


I conducted a static analysis of DeepSeek, a Chinese LLM chatbot, photorum.eclat-mauve.fr utilizing variation 1.8.0 from the Google Play Store. The goal was to recognize potential security and privacy issues.

I've discussed DeepSeek formerly here.

Additional security and privacy concerns about DeepSeek have been raised.

See likewise this analysis by NowSecure of the iPhone version of DeepSeek

The findings detailed in this report are based purely on static analysis. This indicates that while the code exists within the app, there is no definitive evidence that all of it is carried out in practice. Nonetheless, the presence of such code warrants analysis, particularly given the growing concerns around data personal privacy, security, the prospective abuse of AI-driven applications, and cyber-espionage characteristics between worldwide powers.

Key Findings

Suspicious Data Handling & Exfiltration

- Hardcoded URLs direct data to external servers, raising concerns about user activity tracking, such as to ByteDance "volce.com" endpoints. NowSecure recognizes these in the iPhone app the other day too. - Bespoke file encryption and information obfuscation methods exist, with indications that they might be utilized to exfiltrate user details.