Chinese Hackers Use DeepSeek AI to Boost Cyberattacks

Holographic robot analyzing cyberattack code on screens

Written by

in

Chinese state-affiliated cyber groups have more than doubled their attack volume since incorporating DeepSeek and other open-source artificial intelligence models into their operations, according to TeamT5, a Taiwanese threat intelligence firm. The hackers are now using AI to handle routine tasks and to develop sophisticated malicious software, giving them faster and more scalable offensive capabilities.

Why DeepSeek Is the Preferred Model

Researchers at TeamT5 found that DeepSeek’s offerings have become the AI of choice for Chinese hackers because of high performance, strong customization capabilities, and relatively weak built-in cybersecurity guardrails. Open-weight models from Western providers are also popular, but their safety restrictions are stricter and require significantly more effort to bypass.

Cost is another decisive factor. While other Chinese models such as Moonshot’s Kimi K3 are more powerful on paper, they remain prohibitively expensive for hackers to operate at scale, and TeamT5 has not recorded any incidents involving Kimi K3 to date.

How Attackers Are Using the Model

DeepSeek and similar open-weight models are now being deployed across multiple stages of the attack chain, from initial reconnaissance through vulnerability exploitation. In recent months, TeamT5 researchers obtained scripts and logs showing Chinese government-affiliated hackers using the model throughout their operations.

Three named groups illustrate the pattern. The group Grimfengxi used DeepSeek to create exploit codes. A second group, Huapi, used a Chinese AI model, likely DeepSeek, to attack a Taiwanese company’s email system. A third group, Teleboyi, used the platform to collect 1,000 IP addresses from the internet and map company domains for further targeting.

What the Findings Mean for Defenders

The doubling of attack volume shows that open-weight AI models have lowered the cost and skill threshold for state-aligned offensive operations. Researchers note that it is not always possible to identify which specific AI model was used in a given attack, since outputs can be obfuscated, but the operational signatures and tooling suggest widespread adoption of DeepSeek in particular.

For defenders, the practical takeaway is that reconnaissance, exploit development, and target enumeration are increasingly automated. Security teams should expect faster iteration on exploits, more personalized phishing and email attacks, and broader scanning across corporate IP ranges. Monitoring for AI-generated artifacts in malicious scripts and tightening email and perimeter defenses are the most direct responses.

FAQ

What did TeamT5 find about Chinese hackers and DeepSeek?

TeamT5 reported that Chinese state-affiliated cyber groups have more than doubled their attack volume since incorporating DeepSeek and other open-source AI models into their operations, using the models for tasks ranging from reconnaissance to exploit development.

Why do Chinese hackers prefer DeepSeek over Western AI models?

DeepSeek offers high performance and strong customization at low operational cost, and its built-in cybersecurity guardrails are relatively weak. Western models are more sought-after for capability but require substantially more effort to bypass their safety restrictions.

Which hacker groups were identified as using DeepSeek?

TeamT5 named three groups: Grimfengxi, which used DeepSeek to create exploit codes; Huapi, which used a Chinese AI model, likely DeepSeek, to attack a Taiwanese company’s email system; and Teleboyi, which used the platform to collect 1,000 IP addresses and map company domains.


This article summarizes reporting from yahoo.com.