Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Fake AI Large Model Application Subscription Fee Scam: Disguising as Official Channels with Low-Price Traffic Attraction to Induce Payment

The main targets are ordinary small and medium-sized business owners, independent content creators, and students who have a demand for artificial intelligence technology but lack professional computer knowledge. The psychological weakness of victims lies in their unfamiliarity with official channels, desire for bargains, and eagerness to use popular tools. They are easily misled by seemingly cost-effective terms such as local deployment and lifetime membership, hastily scanning codes to pay without verifying domain names and developer qualifications. Once they find it unusable or are blocked, they have often missed the best window for protecting their rights.

SCAM

Key Fields

FIELD STAMPS
IndustryAI / LLM
RegionChina(全国)
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The main targets are ordinary small and medium-sized business owners, independent content creators, and students who have a demand for artificial intelligence technology but lack professional computer knowledge. The psychological weakness of victims lies in their unfamiliarity with official channels, desire for bargains, and eagerness to use popular tools. They are easily misled by seemingly cost-effective terms such as local deployment and lifetime membership, hastily scanning codes to pay without verifying domain names and developer qualifications. Once they find it unusable or are blocked, they have often missed the best window for protecting their rights.

骗局怎么运作

  • Imitating brand names to build websites and attract traffic: Gray-industry syndicates purchase keywords on search engines on a large scale or upload copycat applications with highly similar names and icons on regular app stores. Taking advantage of ordinary users' inability to distinguish official domain names, they precisely direct search traffic to fake websites or copycat applications, intercepting real users' access requests through visual confusion and planting consumption traps.
  • Packaging rhetoric to induce payment: Landing pages promote highly tempting low-price slogans such as forty-nine yuan for local deployment and one hundred ninety-eight yuan for a lifetime membership, implying that official fees are expensive and that such channels are internal cracked versions or low-cost wholesale channels. They exploit users' pursuit of cost-effectiveness to create a sense of scarcity and urgency, prompting impulsive purchases.
  • Disguised customer service multi-step trap: When users click to purchase, the page usually does not directly redirect to regular payments, but instead guides them to so-called customer service WeChat or instant messaging accounts. Customer service sends forged authorization success screenshots or download links, lying that additional activation fees or server configuration fees must be paid, further extracting money from victims.
  • Shell interfaces disconnected at any time: Some victims can indeed use some services briefly after paying, but the underlying backend actually calls other low-cost open-source model interfaces or stolen official interface keys. Once the official strictly investigates and bans accounts or interface quotas are exhausted, copycat applications immediately shut down, and customer service blocks and loses contact with victims, completely completing the harvest.
  • Maliciously stealing private data: During the process of installing the so-called local deployment package or using the copycat application, the software secretly requests non-essential permissions such as contacts, text messages, and photo albums, stealing and packaging private data from the user's device and selling it downstream to the black-and-gray industry chain, leading victims to face threats of spam marketing and even precise telecom fraud.

红旗信号(看到这些快跑)

  • 🚩 Domain names or application names are highly similar to well-known large models but have spelling variations, and are not filed or certified on official lists, allowing ordinary users to be easily hoodwinked if they are not careful.
  • 🚩 Claiming that tens of billions of parameter large models with extremely high computing requirements can be permanently used or locally deployed at extremely low prices completely violates basic computer science common sense.
  • 🚩 Customer service communication is only conducted through personal social accounts, refusing to provide company corporate accounts, regular invoices, and legally valid verifiable service agreements.
  • 🚩 Download links are mostly direct installation package links from non-regular app stores or personal cloud disk shares, and mobile phones frequently report viruses or request unnecessary high-level permission authorizations during installation.
  • 🚩 Shortly after payment, account logouts or complete service interruptions occur. When contacting the seller again, victims encounter evasion, ignored messages, or are directly blocked and deleted with a refusal to refund.

真实案例

  • According to media reports in March 2025, as DeepSeek exploded in popularity, nearly three thousand knockoff websites emerged online to latch onto the hype, luring users to pay under the guise of tens of yuan for local deployment or hundreds of yuan for lifetime memberships, while actually only providing inferior wrapped services or directly scamming money.
  • Media reports in June 2026 showed that scams involving third parties selling ChatGPT premium accounts at low prices appeared in multiple regions. After victims paid hundreds of yuan to buy so-called low-cost shared accounts, they encountered strict official account bans, rendering the accounts unusable while the sellers fled and lost contact.
  • According to disclosures by cybersecurity agencies in August 2026, a syndicate on Telegram engaged in fraud under the name of low-cost top-ups for well-known AI assistant services, which were actually empty phishing links. After transferring money, victims did not receive subscription services and were secretly implanted with Trojan horse programs to steal crypto assets.
  • In February 2026, the State Administration for Market Regulation announced five typical cases of unfair competition in the field of artificial intelligence. Among them, the Chaoyang District Market Regulation Bureau of Beijing investigated and handled the case where Beijing Ouland Information Technology Co., Ltd. used the internet to implement confusion. The party concerned operated a website to promote so-called DeepSeek local deployment tools and used DeepSeek wording and official icons in multiple places to latch onto the hype, which was determined to constitute confusion-based unfair competition and was investigated and punished according to law. (Source: [https://news.cctv.com/2026/02/06/ARTI73n8vCvXOTPmWstYokAm260206.shtml](https://news.cctv.com/2026/02/06/ARTI73n8vCvXOTPmWstYokAm260206.shtml))
  • In February 2025, the National Computer Virus Emergency Response Center released an early warning stating that it captured an Android mobile phone Trojan horse virus disguised as the official DeepSeek app targeting Chinese users. This counterfeit program induced users to update and requested background and accessibility permissions, intercepting text messages to steal contacts and preventing uninstallation. It was identified as a new variant of financial theft Trojan horse virus, potentially used for telecommunication network fraud. (Source: [https://tech.ifeng.com/c/8h2vuB6y5iL](https://tech.ifeng.com/c/8h2vuB6y5iL))

Official Stance

  • On March 15, 2025, Sina Finance, combined with multiple security agencies, released a warning reminding consumers to be wary of local deployment and lifetime membership scams under the names of well-known large models, and to recognize official access channels.
  • On June 13, 2026, cybersecurity media released an early warning prompt, clearly pointing out that third-party low-cost proxy top-ups for overseas AI accounts carry extremely high financial security risks, and official strict crackdowns easily lead to frequent account logouts with nowhere to seek recourse.
  • On August 7, 2026, security agencies released an anti-fraud notice warning that black-market top-up services on communication software like Telegram are all empty phishing shells, and urging users not to transfer money or provide personal account credentials to unknown third parties.

How to Protect Yourself

  • ✅ Be sure to download clients through official websites of well-known large models or regular mobile app stores, recognize official domain names and developer authentication logos, and do not click on promotional links of unknown origin in search engine results for downloading.
  • ✅ Keep in mind the laws of computing cost, remain highly vigilant against marketing rhetoric claiming extremely low prices to provide top-tier large model local deployment or lifetime usage services, and do not believe marketing inducements that violate technical common sense.
  • ✅ Strictly verify payee information before payment, refuse to transfer money to personal social accounts and unknown corporate accounts, and retain chat records, payment screenshots, and download page screenshots throughout the process as key evidence for subsequent rights protection.
  • ✅ Carefully review the privacy permissions requested when installing third-party applications. If high-risk permissions unrelated to chat functions, such as reading text messages or accessing contacts, are requested, immediately refuse and thoroughly uninstall the software.