Taiwan Cyber Threat Specialist Revealed
Used to Develop High Performance Malicious Software
“Strong yet Low Security Limitations”
A study found that Chinese cyber hacker organizations have more than doubled the scale of attacks using artificial intelligence (AI).
According to Bloomberg on the 24th (local time), Taiwan’s cyber threat intelligence (CTI) security company Team T5 announced that hacker organizations linked to the Chinese government are using open-source AI models such as DeepSeek to expand attacks on overseas targets.
The researchers explained that the AI model used by hackers cannot be specified in all cases, but overall, DeepSeek is gaining popularity among Chinese hackers. This is because high performance and user customization are possible, and cybersecurity restrictions are relatively loose and operating costs are low.
Team T5 chief analyst Charles Lee said, “Depsyk is the most preferred AI for Chinese hackers because it is relatively powerful and has very few cybersecurity restrictions. Western models are also preferred, but restrictions are much stricter, so more effort is needed to circumvent them.”
Chinese hacker organizations have been shown to have used AI not only for simple and repetitive tasks but also for developing advanced malicious software. It has been used in most stages, from reconnaissance activities to investigating targets in advance to creating means to attack vulnerabilities.
In fact, a hacking organization named “Grimfengxi” was found to have created code for vulnerability attacks using DeepSeek. Huapi used a Chinese-made AI model to attack Taiwanese companies’ email systems, which Team T5 believes are likely to have been DeepSeek. Using AI, “Teleboyi” collected 1,000 IP addresses from the Internet and identified the domain of a company.
Cases in which US AI models such as ChatGPT and Claude were used for cyberattacks were also detected. According to Team T5, an organization called “Slime22” used Claude code to perform lateral movement (a tactic to acquire account information from an internal network after the first hacking and move to another system). They seem to have circumvented AI’s security restrictions by pretending to be engineers performing cybersecurity tests. It has also been confirmed that a company selling hacking software used ChatGPT in the process of attacking a Western think tank.
On the other hand, there has been no confirmation of the use of Moonshot AI’s “Kimi K3” for hacking. The researchers analyzed that the operating cost of the Kimi K3 is too high for hackers to use.
#
Click Here For The Original Source.
