1 week ago
DeepSeek Helps Chinese Hackers Scale Up Cyberattacks, Researchers Say
Some Chinese hacking groups are using artificial intelligence to help with cyberattacks.
Researchers say these groups have more than doubled their attack activity since adopting AI tools.
DeepSeek is popular because it is relatively cheap, powerful and easier to customize.
Hackers reportedly use AI to find targets, study computer systems and write harmful code.
One group used a model believed to be DeepSeek against a Taiwanese company’s email system.
Other hackers reportedly used ChatGPT to help decrypt data taken from a compromised computer.
Another group used Claude Code to move through a Taiwanese technology company’s systems.
The companies behind these AI tools say they work to stop misuse, and Anthropic said it blocked Chinese-controlled companies.
Researchers said they could not always determine exactly which AI model hackers used.
Chinese state-affiliated hacking groups more than doubled their attacks after adopting AI for routine tasks and malicious-software development, TeamT5 said.
Researchers identified DeepSeek as a popular tool because it is relatively powerful, inexpensive, customizable and has limited cybersecurity guardrails.
Groups reportedly used DeepSeek and other models for reconnaissance, vulnerability exploitation, domain mapping and exploit-code development.
TeamT5 linked DeepSeek or a likely DeepSeek-based model to activity by groups called Grimfengxi, Huapi and Teleboyi.
Chinese-linked hackers also reportedly used ChatGPT and Anthropic’s Claude Code, including in attacks involving a Western think tank and a Taiwanese technology company.
- Who
- TeamT5 and CyCraft researchers described activity by Chinese state-affiliated or state-linked hacking groups, including Grimfengxi, Huapi, Teleboyi and Slime22.
- What
- The groups reportedly used DeepSeek and other AI models to automate and expand cyberattacks, develop malicious software and move through compromised systems.
- Where
- Reported targets included companies and institutions in Taiwan and the West, including a Taiwanese technology company and a Western think tank.
- When
- Researchers said the increase occurred after the groups began using AI; evidence included screenshots taken as recently as February and activity observed in recent months.
- Why
- The hackers used AI to handle routine attack tasks, conduct reconnaissance, generate exploit code and support other stages of cyber operations.
Key facts
- Reported attack increase
- TeamT5 said Chinese state-affiliated groups more than doubled their attack volume after adopting AI.
- Preferred model
- Researchers said DeepSeek was popular because of its performance, low operating cost, customizability and relatively limited cyber guardrails.
- Reported DeepSeek uses
- The model was reportedly used for reconnaissance, exploit-code creation, vulnerability attacks and domain mapping.
- Groups identified
- TeamT5 named Grimfengxi, Huapi and Teleboyi in connection with reported AI-assisted activity.
- Hacking-software startup
- A startup of about 10 employees reportedly sold hacking tools for 300,000 to 500,000 yuan, or approximately $44,500 to $74,000.
- Reported Claude Code operation
- TeamT5 said Slime22 used Claude Code to conduct lateral movement inside a Taiwanese technology company.
- Anthropic disclosure
- Anthropic said Chinese state-backed hackers used Claude Code in September to autonomously target 30 entities.
Quotes
Charles Li
Chief analyst at Taiwanese cybersecurity research firm Team T5
“DeepSeek is the AI of choice for Chinese hackers because it's relatively powerful with very low cyber guardrails. Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass.”
NDTV









