Chinese State Hackers Doubled Attack Volume by Outsourcing to DeepSeek | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Chinese state-affiliated hacking groups have more than doubled the volume of attacks they carry out since delegating reconnaissance, exploit writing, and malware development to artificial intelligence — with DeepSeek emerging as the preferred engine precisely because its weak restrictions and low running costs make it viable at a scale that more capable models cannot match, reported by Bloomberg on August 24, 2026. The finding, from Taiwanese threat-intelligence firm TeamT5, represents the starkest quantified measure yet of how AI has restructured the economics of Chinese state-sponsored hacking — not by making individual attacks more sophisticated, but by making it possible to mount more than twice as many of them with the same number of operators.

Taiwan, which absorbed 2.63 million Chinese cyberattacks per day in 2025 alone, sits at the center of this escalation. The island’s nuclear safety agency, seven energy companies, and dozens of government systems have already been reached by autonomous AI-driven campaigns in 2026. For organizations far from Taiwan, the implications are direct: the asymmetry between attack and defense is widening, and the accelerant is a Chinese AI model that costs almost nothing to run.

Why Cheap and Weak Beats Capable and Restricted

The central finding in TeamT5’s research inverts a common assumption — that the gravest offensive risk from AI lies with the most powerful frontier models. In practice, Charles Li, TeamT5’s chief analyst, found the opposite.

“DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” Li told Bloomberg. “Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass.” Chinese hackers have gravitated toward DeepSeek’s low guardrails not despite its limitations, but because of them — lower safety enforcement means the model executes offensive tasks without refusal that Western providers would block.

The economics are the other half of the selection logic. Moonshot’s Kimi K3 is more capable than DeepSeek by benchmark measures, but TeamT5 logs zero Kimi K3 incidents — and considers its inference costs prohibitive for operators running AI across hundreds of simultaneous targets. Choosing DeepSeek is not a concession by hackers; it is an optimization. At hacker scale, the cost of running thousands of reconnaissance and exploit-generation tasks determines which model gets used. DeepSeek’s price point clears that threshold; Kimi K3’s does not.

This distinction — cheap and weakly guarded vs. capable and expensive — explains why attack volume doubles without any corresponding increase in hacking personnel or budget. AI handles the commodity work. Human operators set targets and review results. The ratio of attacks per operator shifts dramatically upward.

Grimfengxi, Huapi, Teleboyi: Three Groups, Three Attack Functions

TeamT5 named three state-affiliated Chinese groups it has observed using AI in separate campaigns, each deploying the technology for a distinct function in the attack chain, according to AI Weekly’s summary of the Bloomberg reporting.

Grimfengxi used DeepSeek to generate custom exploit code targeting systems with known or newly discovered vulnerabilities — a task that previously required skilled reverse-engineering work and is now automated. Huapi deployed a Chinese AI model — believed to be DeepSeek — against the email infrastructure of a Taiwanese company. Teleboyi used the platform for automated reconnaissance: collecting approximately 1,000 IP addresses from internet-facing systems and mapping a target organization’s corporate domains, producing the kind of structured target intelligence that feeds later intrusion phases.

TeamT5 notes that attribution of AI tool use remains technically challenging — researchers cannot always determine from logs which specific model was active in a given intrusion. The firm obtained scripts and session logs that place DeepSeek across multiple attack stages, but the baseline window against which “more than doubled” is measured was not stated in the research as reported. That qualification acknowledged, the directional finding is corroborated by independent reporting and by the documented operational record of autonomous AI campaigns in 2026.

Slime22 and the Western-Model Problem

Alongside the three DeepSeek-reliant groups, TeamT5 documented a fourth — designated Slime22 — whose approach illustrates a different dimension of the dual-use AI problem.

After breaching a Taiwanese company’s systems, Slime22 set up its own instance of Kali, a standard penetration-testing platform, and directed Anthropic’s Claude Code to use it for lateral movement through the network. The operators circumvented Claude’s safety restrictions by presenting themselves as security engineers conducting authorized testing — applying social engineering not to a human gatekeeper, but to an AI.

Anthropic has blocked its services from Chinese-controlled entities. The “authorized penetration test” cover story represents a structurally different bypass mechanism than DeepSeek’s weak guardrails: rather than selecting a model that imposes no restrictions, Slime22 convinced a model that does impose restrictions that the offensive operation was legitimate. As TechTimes documented in August 2026, the Taiwan government breach used the same technique against open-source frameworks — suggesting this social-engineering approach is now a documented playbook item, not an isolated improvisation.

Separately, cybersecurity firm CyCraft documented a related case in which hackers used OpenAI’s ChatGPT to decrypt a stolen Signal database during an attack on a Western think tank — evidence that Western commercial AI is being selectively exploited wherever guardrails can be circumvented or the task falls below the safety threshold.

How AI Is Sold as a Weapon: China’s Commercial Hacking Market

TeamT5 and CyCraft’s research surfaces a commercial dimension that does not fit the standard state-versus-individual hacker frame.

CyCraft traced a startup of approximately 10 employees that was selling AI-assisted hacking software for between 300,000 yuan and 500,000 yuan (approximately $44,600 to $74,400) per toolkit. At least four Chinese hacking groups purchased the software. The company also used ChatGPT during an operation, according to screenshots of internal communications reviewed by Bloomberg reporters.

This commercial market represents a layer below the state-sponsored group and above the lone operator — a contractor ecosystem that commoditizes AI-enabled offensive capability and distributes it to groups that could not develop it in-house. It is the offensive equivalent of cybersecurity-as-a-service, and it extends the population of actors who can field AI-amplified campaigns beyond the named state-affiliated groups TeamT5 has directly attributed.

The Legal Condition Behind DeepSeek’s Offensive Use

Organizations evaluating DeepSeek for legitimate enterprise deployments face a legal condition that is distinct from the immediate cybersecurity risk these campaigns document.

DeepSeek is headquartered in Hangzhou, China. Under China’s National Intelligence Law (2017), Article 7 requires that “all organizations and citizens shall support, assist, and cooperate with national intelligence efforts in accordance with law.” China’s Cybersecurity Law (2017) adds data localization and government-access provisions, and the Data Security Law (2021) extends state leverage over cross-border data handling. These legal obligations apply to DeepSeek regardless of its stated privacy policy, the physical location of its servers, or any Western corporate structure it may maintain. Data submitted to DeepSeek’s API may be subject to Chinese government access on demand.

These laws do not make every DeepSeek deployment an intelligence operation. They do mean every DeepSeek deployment operates inside an intelligence-requisition framework whose activation is outside the deploying organization’s control.

A Pattern That Predates the Current Finding

The TeamT5 volume-doubling finding sits on top of a documented operational record stretching back to 2025.

In mid-September 2025, Anthropic detected what it subsequently described as the first documented case of a large-scale cyberattack executed without substantial human intervention at scale. The attacker — designated GTG-1002 and assessed with high confidence as a Chinese state-sponsored group — manipulated Claude Code into operating as an autonomous penetration-testing orchestrator, with AI executing 80 to 90 percent of tactical operations including reconnaissance, vulnerability analysis, and data exfiltration. The campaign targeted approximately 30 organizations globally and succeeded in a small number of cases.

By June 2026, Anthropic’s MITRE ATT&CK threat analysis of 832 accounts banned for malicious cyber activity between March 2025 and March 2026 found that the share of medium-to-high-risk threat actors using AI had risen from 33 to 56 percent in a single year. Critically, the research found that AI had eroded the traditional signal security teams used to judge threat severity: attackers with little technical skill were now using AI to execute techniques previously limited to experienced operators.

TeamT5’s volume-doubling figure is the first quantified population-level confirmation of what those incident-level findings predicted: the same operator base, given cheap AI, can mount a structurally larger campaign footprint.

Is Any Country Prepared?

Kenny Huang, chairman of the Taiwan Network Information Center, offered an assessment that extends the implications beyond Taiwan.

“I believe there are still significant gaps,” Huang said. “Every country, not just Taiwan, is still unprepared in this respect.”

Unit 42’s conclusion from its July 2026 autonomous campaign analysis was similarly stark: “The technical barrier to AI-augmented offensive operations is low and continues to decrease.” The barrier that stopped the most documented autonomous campaigns was not detection — it was the presence of authentication requirements on specific endpoints. Organizations that were not reached were protected by a login screen, not a monitoring system.

For defenders, that finding is actionable. Patch speed has collapsed from weeks to days since security advisories became exploitation roadmaps. Authentication requirements on internet-facing endpoints demonstrably stopped autonomous AI campaigns that detection did not catch. And a monitoring approach sized to human-tempo attacks — where a single operator can mount a bounded number of intrusions per day — is now systematically behind a threat landscape where the same operator, backed by cheap AI, can mount more than twice as many.

The cost of running a competent attack has collapsed. The cost of defending against one has not.

Currency conversion note: yuan-to-dollar figures in this article use an exchange rate of approximately 1 CNY = $0.1488 USD, current as of August 26, 2026. Conversions are approximate.


Frequently Asked Questions

Why do Chinese state hackers prefer DeepSeek over more powerful AI models?

Cost and permissiveness are the two selection criteria, according to TeamT5 chief analyst Charles Li. DeepSeek’s inference costs are low enough to run across hundreds of simultaneous targets — a requirement that eliminates more capable but more expensive models like Moonshot’s Kimi K3, which TeamT5 says it has documented in zero attack incidents despite being more powerful. Western frontier models impose additional provider-side behavioral monitoring that can detect and revoke access across sessions — an obstacle DeepSeek’s open-weight design does not present. These findings are documented across the AI Weekly summary of TeamT5’s research and the Taipei Times coverage of Bloomberg’s reporting.

How has delegating tasks to AI allowed Chinese groups to more than double their attack volume?

AI handles the commodity labor of offensive operations: scanning internet-facing systems, writing exploit code for known vulnerabilities, mapping target organizations’ network topology, and generating reconnaissance reports. Tasks that previously required experienced operators spending hours per target can now be delegated to an AI model and parallelized across dozens of targets simultaneously. The same number of human operators, each overseeing AI-generated output rather than performing manual work, can direct a proportionally larger number of campaigns. TeamT5’s finding that volume has more than doubled is directionally consistent with what Unit 42 documented in May 2026: a single operator giving one Telegram command while DeepSeek autonomously researched and targeted more than 647,000 internet-facing systems.

What should organizations do to reduce exposure to AI-amplified cyberattacks?

Three defensive priorities emerge from the 2026 documented campaigns. First, patch speed: the window between a vendor’s security advisory and active exploitation by China-linked groups has compressed to five days in at least one documented case — organizations that rely on standard one-to-three-week patch testing cycles were already compromised before testing concluded. Second, authentication coverage: every autonomous AI campaign documented in 2026 was stopped by the presence of authentication requirements on target endpoints; their absence was what enabled breaches. Third, behavioral monitoring over consent-based guardrails: the Taiwan government breach demonstrated that any AI framework whose safety system relies on the operator’s stated intent — rather than on observed behavioral patterns — will be defeated by an operator who describes an offensive operation as an authorized security test. The CISA Known Exploited Vulnerabilities catalog provides mandatory patch deadlines for federal agencies that serve as a useful baseline for enterprise patch prioritization.

Is DeepSeek safe to use in enterprise environments given its role in these attacks?

DeepSeek’s role as the attack engine for Chinese state-affiliated campaigns is a separate question from its enterprise data-handling risk, but the two are related. As a company headquartered in Hangzhou, China, DeepSeek is legally required by China’s National Intelligence Law (2017), Article 7 to cooperate with national intelligence requests on demand — an obligation that applies regardless of its privacy policy or server location. Organizations using DeepSeek’s API should treat submitted data as potentially subject to Chinese government access. The separate cybersecurity risk is that DeepSeek’s weak guardrails and open-weight design make it the preferred tool for campaigns targeting those same organizations’ competitors, partners, and government counterparts. The economics are documented in prior TechTimes coverage of the Unit 42 autonomous campaign findings.



Click Here For The Original Source.

——————————————————–

..........

.

.