Chinese state-linked hacking groups have more than doubled their attack output after wiring low-cost artificial intelligence models into their operations, according to Taiwanese threat intelligence firm TeamT5.
The firm said operators are delegating reconnaissance, exploit writing, and movement inside breached networks to open-source AI, work that once required larger teams of people. The preferred tool is DeepSeek, a Chinese model favored for its low running cost and weak safety controls.
“DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” said Charles Li, chief analyst at TeamT5. Western models are in demand, he said, but their guardrails take far more effort to bypass.
The finding points to a shift most defenders have not priced in. The offensive AI threat is widely assumed to sit with the most advanced frontier systems. TeamT5’s evidence indicates the opposite. Operators are scaling attacks with weaker, cheaper tools, and cost and permissiveness drive the choice. Researchers said they have not recorded an incident involving Moonshot’s more capable Kimi K3 model, which they believe is too expensive to run at hacker scale.
TeamT5 said it obtained scripts and logs in recent months placing DeepSeek across multiple stages of an operation, not only at the start. A group the firm tracks as Grimfengxi used DeepSeek to write exploit code. Another, Huapi, used a Chinese model researchers believe was DeepSeek to attack a Taiwanese company’s email system. A third, Teleboyi, used it to collect 1,000 IP addresses and map a target’s domains.
Some operators reached for American tools. A group tracked as Slime22 used Anthropic’s Claude Code to move laterally inside a Taiwanese technology firm, TeamT5 said. The group installed the Kali penetration testing platform, a common toolkit for probing networks, and posed as an engineer running security tests to bypass the tool’s guardrails.
Cybersecurity firm CyCraft said a vendor of hacking software used ChatGPT during an attack on a Western think tank, asking the chatbot to help build a module to decrypt an employee’s stolen Signal database.
The clearest sign that AI-enabled attack tooling is becoming a commercial product came from a public shared drive TeamT5 found holding thousands of Chinese-language screenshots taken as recently as February. The images showed a roughly 10-person startup building hacking tools for sale, charging 300,000 to 500,000 yuan, about $44,500 to $74,000, per package. Its customers were at least four separate groups. Activity tied to one overlaps with Mustang Panda, which the U.S. Justice Department says is backed by the Chinese government.
The pattern extends beyond frontier tools that have drawn most of the attention. Anthropic said last year that a Chinese state-backed group used Claude Code in September 2025 to autonomously carry out attacks on about 30 entities, including large technology firms, financial institutions, chemical manufacturers, and government agencies. The company called it the first documented case of a large-scale cyberattack executed without substantial human intervention. Anthropic has since blocked its services from Chinese-controlled companies.
DeepSeek, China’s embassy in Washington, and its Ministry of Foreign Affairs offered no public statement. Anthropic has not commented. An OpenAI spokesperson said the company is committed to identifying, preventing, and disrupting attempts to abuse its models.
The turn toward local, weakly guarded models is not confined to China. South Korean firm Genians reported this month that North Korea’s Kimsuky group has begun running open models such as Ollama, GPT4All, and Msty on its own machines, a setup that keeps its work off commercial platforms that log activity and screen for abuse.
TeamT5 said it was not always possible to identify which model an operator used in a given intrusion.
Click Here For The Original Source.
