Chinese State-Linked Hackers Turn to DeepSeek as AI Supercharges Cyberattacks

Artificial intelligence is rapidly changing the cybersecurity landscape, and recent research suggests that state-linked hacking groups are increasingly using AI tools to expand their operations. Taiwanese cybersecurity research firm TeamT5 has discovered that DeepSeek and other artificial intelligence models are being used by Chinese government-linked hackers in a number of areas including exploit code development, reconnaissance of malware and software development.

Chinese Hackers Using DeepSeek to Scale Cyberattacks | Photo Credit: AI Images
Chinese Hackers Using DeepSeek to Scale Cyberattacks | Photo Credit: AI Images

According to the research cited by Bloomberg, hacking groups have significantly increased the scale of their operations since incorporating AI into their workflows. TeamT5 researchers reported on how some Chinese hacking groups more than doubled the number of attacks they carried out after they started to use artificial intelligence to build malicious software and support other technical tasks.

The results reflect a very real concern in the cybersecurity industry: attackers do not need access to the most advanced AI systems to become more powerful. Even relatively cheap and widely available models can help hackers automate repetitive tasks, analyze information and accelerate parts of an attack campaign.

Why DeepSeek Is Attracting Hackers

DeepSeek has been particularly popular among Chinese hacking groups because of its relatively low cost, strong capabilities and fewer restrictions on some specific cybersecurity-related requests. Charles Li, chief analyst at TeamT5, said Chinese hackers are interested in DeepSeek because Western AI models are more robust in terms of potential security risks.

According to the researcher, Western AI systems are still coveted but their stricter safety mechanisms can make it harder to recruit malicious actors who are looking to help with hacking-related tasks. DeepSeek's relatively permissive approach has made it attractive for organizations looking to integrate AI into their existing operations, he added.

However, the problem goes beyond one AI platform. Security researchers have repeatedly warned that large language models can lower the technical barriers involved in some stages of cyberattacks. Tasks that previously required a lot of time or specialist knowledge can be accelerated when attackers use AI to analyze code, generate scripts, process information or automate reconnaissance.

Several Chinese Groups Reportedly Experimenting With AI

TeamT5 reported finding scripts and operational logs that showed that several Chinese government-linked groups have incorporated AI into their activities. Researchers also discovered different groups are using AI for different purposes, indicating the technology can support multiple stages of a cyber operation.

One group (Grimfengxi) is said to have used DeepSeek to create the exploit code. A group called Huapi allegedly used DeepSeek technology to hack into the email system of a Taiwanese firm.

A third group, Teleboyi, reportedly used AI-assisted methods to collect around 1,000 internet-facing IP addresses and map domains of a company. This kind of reconnaissance can help attackers get a better picture of an organization's online infrastructure before getting involved in any further intrusions.

These examples show AI’s ability to help hackers not only to write malicious software, but to help with information gathering, mapping of infrastructure and programming and such other activities that are a part of cyberattack.

US AI Models Also Being Used

The activity is not limited to Chinese-developed AI systems. Researchers have also found evidence that Chinese hackers have used American AI platforms during cyber operations.

Cybersecurity company CyCraft discovered evidence that a hacking software firm used ChatGPT when targeting a Western think tank. The hackers asked for help in developing software that decrypts data from an employee’s compromised computer.

Anthropic's Claude tools have also been targeted for abuse. TeamT5 said that Slime22 used Claude Code after gaining access to a Taiwanese technology company. Anthropic then blocked its services from Chinese-controlled companies, illustrating the increasing difficulty AI companies face in preventing their platforms from being misused by malicious actors.

AI Could Increase the Scale of Cyber Threats

The latest findings underscore a broader shift in the cyber threat landscape. Traditionally, sophisticated cyberattacks might require teams of specialists working with programming, reconnaissance, vulnerability research and infrastructure management. AI tools could potentially automate or accelerate those processes.

That creates a complicated picture for cybersecurity defenders. Security teams must protect systems from the usual malware and phishing campaigns but also the attackers who might be using AI to adapt their tactics faster and to run at a larger scale.

At the same time, cybersecurity researchers stress that AI does not automatically turn inexperienced users into elite hackers. Cyber operations still need infrastructure, access, technical expertise and operational planning. However, AI can reduce the time and effort for particular tasks, and that can in turn make existing hacking groups more efficient.

The use of DeepSeek, ChatGPT and Claude clearly illustrate that the AI security problem is not just a single company or model problem but rather is a platform-wide issue. As artificial intelligence becomes more powerful and accessible, technology companies and cybersecurity organizations will be under increasing pressure to increase security safeguards while not stifling the quality of the real research to be done.

The TeamT5 results are another warning about the dual-use nature of artificial intelligence. The same technologies being developed to increase productivity, coding and research can be repurposed by sophisticated threat actors. As governments, businesses and AI companies continue to evolve with this changing world of business, preventing AI-assisted cyberattacks is going to be a priority of the global cybersecurity industry.