🏠 News Empire
tech

Chinese State-Linked Hackers Using DeepSeek AI to Ramp Up Cyberattacks: Researchers

Published on: 25 Aug 2026, 04:53 AM
Chinese State-Linked Hackers Using DeepSeek AI to Ramp Up Cyberattacks: Researchers

Cybersecurity researchers have found that Chinese state-affiliated hackers are increasingly using DeepSeek and other open-source artificial intelligence models to scale up their cyber operations. The findings, from Taiwan-based research firm TeamT5, highlight how attackers are leveraging relatively basic AI tools to hit targets abroad.

According to TeamT5, state-linked cyber groups have more than doubled the number of attacks they carry out since they began delegating routine tasks to AI and using it to develop more advanced malicious software. The researchers noted that while it was not always possible to identify the exact AI model used, DeepSeek has become popular among hackers in China due to its high performance and ability to be customised.

The report comes amid growing anxiety among US national security officials about the autonomous capabilities of advanced AI models from companies like Anthropic and OpenAI. Recent incidents have seen these models break out of controlled testing environments. However, the researchers say experienced Chinese hackers are using far less capable AI to expand their activities and achieve breakthroughs.

Although other Chinese-made models, such as Moonshot's Kimi K3, are considered more powerful, TeamT5 found that hackers are drawn to DeepSeek because of its relatively lax cybersecurity barriers and low running costs. The researchers added that they have not yet recorded any incident involving Kimi K3, which they believe is prohibitively expensive for hackers to run.

"DeepSeek is the AI of choice for Chinese hackers because it's relatively powerful with very low cyber guardrails," said Charles Li, chief analyst at TeamT5. "Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass."

DeepSeek did not respond to a request for comment. Neither China's Embassy in Washington nor its Ministry of Foreign Affairs responded to messages seeking comment.

TeamT5 reported that DeepSeek, along with a mix of other open-source models, has been adopted throughout multiple stages of an attack, including reconnaissance and generating ways to exploit vulnerabilities. In recent months, researchers obtained scripts and logs showing DeepSeek being used by hackers affiliated with the Chinese government throughout their operations.

Specific instances cited by TeamT5 include a group known as Grimfengxi, which used DeepSeek to create exploit codes. Another group, called Huapi, used a Chinese AI model—likely DeepSeek—to attack the email system of a Taiwanese company. A third group, known as Teleboyi, used the platform to collect 1,000 IP addresses and map a company's domains.

In some cases, Chinese hackers have also turned to American AI. Cybersecurity firm CyCraft reported that a company selling hacking software used ChatGPT during an attack on a Western think tank. After obtaining a copy of an employee's local Signal database from a compromised computer, the hackers consulted the chatbot to help build a software module designed to decrypt it, according to screenshots reviewed by Bloomberg News.

An OpenAI spokesperson said the company is committed to identifying, preventing and disrupting attempts to abuse its models.

Researchers made these discoveries after finding a public shared drive containing thousands of Chinese-language screenshots taken as recently as February. The images show the workflow of a small startup of about 10 employees developing hacking tools for sale. The group charged between 300,000 yuan (about $44,500) and 500,000 yuan (about $74,000) for their software. Its customers were at least four separate hacking groups, each running their own campaigns. Activity linked to one of the groups overlaps with operations publicly attributed to Mustang Panda, which the US Justice Department says is backed by the Chinese government.

Anthropic's tools have also been involved. TeamT5 said a group known as Slime22 managed to use Claude Code to move around inside the systems of a Taiwanese technology company. After breaching the company's systems, the group set up its own system of Kali, a popular penetration testing platform.

The findings underline the dual-use nature of open-source AI models and the evolving threat landscape. While advanced models from Western firms are often the focus of security concerns, this report demonstrates that less sophisticated, openly available tools can still significantly enhance the capabilities of malicious actors.

Latest in Tech 10
Visakhapatnam station trials AI assistant to guide passengers
tech

Visakhapatnam station trials AI assistant to guide passengers

South Coast Railway General Manager Sandeep Mathur inspected passenger facilities at Visakhapatnam Railway Station and reviewed the pilot 'Sarika AI' voice-based assistance system. The AI tool provides real-time train information and station guidance in nine languages, with plans to integrate it into the RailOne app.

The Hindu 17 Aug 2026, 07:00 PM
Read More →
→ View All Tech News