Chinese state-affiliated hacking groups have more than doubled their attack activity by integrating DeepSeek’s artificial intelligence models into their operations, according to researchers at Taiwanese cybersecurity firm TeamT5. The groups are deploying AI across nearly every stage of intrusion campaigns, from reconnaissance and vulnerability research to malware development and exploit creation.
DeepSeek has emerged as the preferred model among multiple Chinese hacking collectives, according to Charles Li, chief analyst at TeamT5. He attributed that preference to the model’s capable performance, low operating costs, and comparatively weak cybersecurity restrictions.
“DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” Li said. “Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass.”
While other Chinese models such as Moonshot’s Kimi K3 offer greater raw capability, their operating costs remain prohibitively expensive for hacking groups, researchers noted. TeamT5 said it has not recorded any incidents involving Kimi K3 to date.
Experienced operators can now complete demanding assignments faster without expanding their teams or investing heavily in additional infrastructure. The technology shortens the time required for reconnaissance, vulnerability analysis, exploit preparation, and network mapping.
TeamT5 identified several groups that allegedly used artificial intelligence during separate campaigns against companies and institutional targets. Grimfengxi reportedly used DeepSeek to generate exploit code for systems containing known or newly discovered security weaknesses. Huapi employed a Chinese AI model while targeting the email infrastructure of a Taiwanese company. Researchers believe the model was DeepSeek, although available evidence did not provide complete confirmation. Teleboyi used the technology to gather roughly 1,000 internet protocol addresses and map corporate domains, information that can help attackers identify exposed services and prepare more targeted intrusion attempts.
Research from Palo Alto Networks’ Unit 42 uncovered another Chinese-linked campaign involving DeepSeek and the Hermes Agent framework. A Chinese-speaking attacker used the framework to locate vulnerable machines, obtain exploitation tools, and initiate attacks with limited supervision. The campaign targeted more than 460 systems, demonstrating how autonomous agents can extend an attacker’s reach across multiple networks while human operators manage objectives and adjust broader strategies.
Chinese attackers have also adopted Western AI models when those platforms provide useful coding or data-processing capabilities. Cybersecurity company CyCraft discovered evidence that a hacking-tool vendor used OpenAI’s ChatGPT while attacking a Western think tank. The attackers compromised an employee’s computer and obtained a locally stored database from the encrypted messaging application Signal, then used ChatGPT to help develop software intended to decrypt information contained within the stolen database.
TeamT5 also connected the Slime22 hacking group with Anthropic’s Claude Code during a Taiwanese technology company breach. Hackers allegedly presented themselves as cybersecurity engineers, allowing them to bypass safeguards restricting harmful requests. They later used the coding model to support movement across the company’s systems following the initial unauthorized access.
The cases indicate that attackers do not need the most advanced AI models to improve their operational capabilities. Affordable open-source models can automate repetitive assignments and provide technical assistance during several stages of an intrusion, enabling skilled hacking groups to investigate more targets while operating with smaller teams and lower infrastructure expenses.
However, AI does not remove the need for experienced operators who understand security weaknesses and can direct automated tools effectively. Cybersecurity teams now face campaigns combining human expertise with automated systems capable of performing complex technical assignments.
Organizations may therefore require stronger monitoring to detect rapid reconnaissance, automated exploitation attempts, and unusual movement across internal networks. AI-assisted cyberattacks are increasing operational speed and scale while lowering barriers that previously limited sophisticated hacking campaigns.
Click Here For The Original Source.
