Chinese Hackers Double Attack Volume Using DeepSeek AI
State-affiliated Chinese hacking groups have doubled their attack volume by integrating DeepSeek and other AI models into their cyber operations.
State-affiliated Chinese hacking groups have more than doubled their attack volume by integrating open-source artificial intelligence models into their operations. Research from TeamT5 indicates that hackers specifically favor DeepSeek due to its high performance, low cost, and minimal cybersecurity guardrails compared to Western alternatives. These tools are utilized across multiple attack stages, including reconnaissance, domain mapping, and the generation of exploit codes.
Identified groups including Grimfengxi, Huapi, and Teleboyi have employed these tactics, with some activity overlapping with Mustang Panda, a group the United States Department of Justice links to the Chinese government. In Taiwan, the group Huapi and another entity known as Slime22 targeted local companies and technology firms.
While DeepSeek is a primary tool, hackers have also bypassed guardrails of American AI models. CyCraft reported a hacking software vendor used ChatGPT to decrypt a Signal database during an attack on a Western think tank. Additionally, Slime22 used Anthropic's Claude Code to perform lateral movements within a Taiwanese technology company by posing as a security engineer. Anthropic previously reported that state-backed hackers used Claude Code in September to autonomously attack 30 entities.