Chinese state-linked hackers use DeepSeek to scale attacks

State-affiliated groups are using low-cost, lightly guarded AI models for reconnaissance, exploit development and other routine work—helping them more than double their attack volume, researchers say.

Share
Chinese state-linked hackers use DeepSeek to scale attacks
Source: RoadMaster19

According to TeamT5, a Taiwanese research firm, Chinese hackers are ramping up attacks after integrating DeepSeek and other open-source artificial intelligence models into their operations, highlighting attackers’ ability to leverage basic AI tools to hit targets abroad.

State-affiliated cyber groups more than doubled the number of attacks they carried out since they began delegating mundane tasks to AI and using it to develop advanced malicious software, TeamT5 reports.

Researchers said it wasn’t always possible to identify the AI model they used, but in general, DeepSeek’s offerings are popular with hackers in the country because of their high performance and ability to be customized.

They also say experienced Chinese hackers are using far less capable AI to scale up their activities and achieve breakthroughs. While other models produced in the country are more powerful – including Moonshot’s breakout Kimi K3 model – hackers are drawn to DeepSeek’s relatively lax cybersecurity barriers and low cost of running, researchers said. They added that they had yet to record an incident involving Kimi K3, which they believe is prohibitively expensive for hackers to run.

“DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” said Charles Li, chief analyst at TeamT5. “Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass.”

Along with a mix of other open-source models, DeepSeek has been adopted throughout multiple stages of an attack, conducting reconnaissance and generating means of attacking vulnerabilities, TeamT5 said. They said in recent months they’ve obtained scripts and logs showing the model being used by hackers affiliated with the Chinese government throughout their operations.

A group known as Grimfengxi used DeepSeek to create exploit code. Another group, called Huapi, used a Chinese AI model, which researchers said was likely DeepSeek, to attack an email system of a Taiwanese company. A third, known as Teleboyi, used the platform to collect 1,000 IP addresses from the internet and map a company’s domains.

In some cases, Chinese hackers turned to American AI for help. The cybersecurity firm CyCraft said a company that sells hacking software used ChatGPT during an attack on a Western think tank. After obtaining a copy of an employee’s local Signal database from a compromised computer, the hackers consulted the chatbot to help build a software module designed to decrypt it, according to screenshots reviewed by Bloomberg News.

Researchers discovered this after finding a public shared drive with thousands of Chinese-language screenshots taken as recently as February. The images show the workflow of a small startup comprising about 10 employees developing hacking tools for sale. They charged between 300,000 yuan ($44,500) and 500,000 yuan ($74,000) for their software. (Mark Anderson / Bloomberg)

Related: Implicator.aien.people.cn, The Chosun Daily, Chosun Biz, NewsBytes, BeInCrypto, Firstpost, Maeil Business


Metacurity is the cybersecurity news you'd need hours to assemble yourself.

Every weekday, we read the releases, filings, court documents, and reports that vendors and PR teams often don't want summarized — then tell you what actually changed and why it matters. Minimum vendor marketing, no outrage bait, no SEO filler.

A paid subscription to Metacurity delivers

  • Full archive access — every newsletter and AI Watch roundup, searchable and browsable.
  • Our weekly curated long-reads roundup — the best cybersecurity writing from across the industry, filtered and vetted so you're not sorting through it yourself,
  • Periodic specialized reports and analyses — deep dives that go beyond our daily coverage
  • Support for independent, no-spin cybersecurity journalism — funded by readers, not vendors or investors.

Reader support is what keeps Metacurity independent. It allows us to focus on serving the cybersecurity community—not advertisers, vendors, or investors—and to continue delivering the thoughtful analysis you've come to rely on every weekday.

Please consider supporting us. And thank you!