Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

bloomberg+1cryptobriefing+1thehackernews+1Chinese state-affiliated hacking groups have more than doubled their attack volume after integrating DeepSeek and other open-source artificial intelligence models into their operations, according to research published Monday by Taiwanese cybersecurity firm TeamT5.
The findings illustrate how basic AI tools, available at low cost and with limited safety restrictions, are enabling experienced threat actors to scale their operations across multiple stages of cyber campaigns.
"DeepSeek is the AI of choice for Chinese hackers because it's relatively powerful with very low cyber guardrails," said Charles Li, chief analyst at TeamT5. "Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass."investing+1
Researchers said DeepSeek's popularity stems from its performance capabilities, low operational costs, and the ease with which it can be customized for malicious purposes. While other Chinese models such as Moonshot's Kimi K3 offer greater power, they remain too expensive for hackers to deploy at scale, according to Bloomberg.bloomberg
TeamT5 identified several groups using the technology. A group called Grimfengxi used DeepSeek to generate exploit code, while Huapi used a Chinese AI model believed to be DeepSeek in an attack on a Taiwanese company's email system. A third group, Teleboyi, used the platform to collect roughly 1,000 IP addresses and map corporate domains.cryptobriefing+1
The research also revealed that Chinese attackers have turned to Western AI tools. Cybersecurity firm CyCraft found evidence that a company selling hacking tools used OpenAI's ChatGPT while targeting a Western think tank, using it to develop software to decrypt a stolen Signal database.cryptobriefing
TeamT5 said a group known as Slime22 used Anthropic's Claude Code after breaching a Taiwanese technology company, presenting themselves as cybersecurity engineers to bypass the model's safeguards.cryptobriefing
Separate research from Palo Alto Networks' Unit 42, published in late July, documented what researchers described as the first fully autonomous offensive AI operation observed in the wild. A Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to target more than 460 systems, successfully breaching at least three organizations through a Citrix NetScaler vulnerability.thehackernews+2
The operator also attempted to use Claude Code and OpenAI's models, but safety measures blocked the malicious requests and ultimately resulted in the account being disabled. DeepSeek, accessed through an open-source framework without client-side restrictions, proceeded without hindrance.bleepingcomputer+2