DeepSeek, ChatGPT and Claude: How Chinese hackers are using AI in cyberattacks | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker


Chinese state-linked hacking groups are increasingly using DeepSeek and other artificial intelligence models to automate routine work and develop malicious tools, according to cybersecurity researchers. The trend suggests that readily available AI, rather than only the most advanced systems, is helping attackers expand the scale and pace of their operations.

Chinese hacking groups are increasingly weaving artificial intelligence into their cyber operations, using models including DeepSeek to automate reconnaissance, write exploit code and assist with movement inside compromised networks, according to cybersecurity researchers cited by Bloomberg.

The shift does not necessarily depend on the world’s most powerful AI systems. Instead, researchers say attackers are finding value in cheaper and more accessible models that can be adapted for specific tasks and used repeatedly throughout an intrusion.

Taiwanese cybersecurity firm TeamT5 told Bloomberg that activity by state-affiliated Chinese groups has more than doubled since they began handing routine tasks to AI and using the technology in the development of more sophisticated malicious software.

Researchers cannot always establish which model was used in a particular operation. But DeepSeek has emerged as a recurring presence in their investigations, partly because of its performance, relatively low operating costs and the flexibility offered by open-source models.

AI takes on reconnaissance and exploit development

TeamT5 said it had recently obtained scripts and operational logs showing AI being used at several points during attacks linked to Chinese government-affiliated hackers.

One group, known as Grimfengxi, used DeepSeek to generate exploit code, according to the researchers. Another, Huapi, is believed to have used a Chinese AI model — likely DeepSeek, though researchers could not confirm this — during an attack on the email infrastructure of a Taiwanese company.

More from Tech

A third group, Teleboyi, reportedly used the platform to gather around 1,000 IP addresses from across the internet and map a company’s domains.

The examples point to a more practical use of AI in cyber operations. Rather than relying on a model to independently carry out an entire intrusion, attackers appear to be using it to speed up individual stages of the process, from gathering information to developing code.

Other Chinese-made models are considered more capable in some areas. Moonshot AI’s Kimi K3, for instance, has attracted attention for its performance. Yet TeamT5 researchers said they had not identified an incident involving the model, which they believe may be too expensive for widespread use by hacking groups.

Chinese hackers have also turned to US-developed AI tools in some cases.

CyCraft, another cybersecurity company, found evidence that a Chinese firm selling hacking software used ChatGPT while targeting a Western think tank. According to screenshots reviewed by Bloomberg, the attackers had obtained an employee’s local Signal database from a compromised device and then consulted the chatbot while developing a software component intended to decrypt it.

The investigation led researchers to a publicly accessible shared drive containing thousands of Chinese-language screenshots, some dated as recently as February. The material appeared to document the work of a small startup of roughly 10 employees developing hacking tools for sale.

The company reportedly charged between 300,000 yuan and 500,000 yuan for its software and counted at least four hacking groups among its customers. Activity associated with one of those groups overlapped with campaigns publicly linked to Mustang Panda, a group the US Justice Department has said is backed by the Chinese government.

Guardrails remain a target

AI companies have spent heavily on safeguards intended to prevent their systems from being used for cyberattacks, but researchers say those restrictions can sometimes be bypassed through carefully framed prompts.

TeamT5 said a group called Slime22 used Anthropic’s Claude Code after gaining access to the systems of a Taiwanese technology company. The group set up its own Kali Linux environment and prompted the AI tool to assist with lateral movement, according to the researchers. They allegedly presented the activity as legitimate cybersecurity testing to get around the model’s safeguards.

Anthropic has restricted access to its services for Chinese-controlled companies and has previously disclosed alleged misuse by Chinese state-backed hackers. The company said last year that attackers had used Claude Code in September to target 30 organisations, including technology firms, financial institutions, chemical companies and government agencies.

Anthropic described that episode as the first documented large-scale cyberattack carried out without substantial human intervention.

The latest findings, however, underline a different concern: hackers may not need frontier-level AI to increase the volume of their operations. As models become cheaper, more widely available and easier to adapt, even relatively basic systems could help experienced operators carry out familiar tasks faster and at greater scale.



Click Here For The Original Source.

——————————————————–

..........

.

.