Chinese State Hackers Double Attack Volume After Adopting AI, Report Shows

  • Chinese state-linked groups doubled attack volume after adopting AI, TeamT5 says.
  • Hackers favor DeepSeek for performance and customization, though attribution stays hard.
  • North Korea's Kimsuky is testing local AI tools for malware development.
Promo

Chinese state-affiliated hackers now run twice as many attacks as they did before handing mundane work to DeepSeek and open-source artificial intelligence (AI) systems, according to Taiwanese threat intelligence firm TeamT5.

Attribution remains imprecise. The firm cannot tie every intrusion to a specific system, though it said that DeepSeek remains a popular choice among hackers.

Sponsored
Sponsored

Why Cheap AI Beats Frontier Models for Attackers

The finding inverts a common assumption that the risk of offensive AI lies mainly with the most advanced systems. Instead, operators are now scaling output using relatively weaker tools.

Cost and permissiveness drive that choice. Moonshot’s Kimi K3 is more powerful. Yet, TeamT5 has logged no incidents involving it and considers its running costs prohibitive for hackers.

Charles Li, chief analyst at TeamT5, framed the trade-off directly.

“DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails. Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass,” Li said.

Follow us on X to get the latest news as it happens

Sponsored
Sponsored

How Hackers Use AI

TeamT5 obtained scripts and logs, placing DeepSeek across multiple attack stages. A group called Grimfengxi used it to generate exploit code. Teleboyi used it to gather 1,000 IP addresses and map a target’s domains. 

Huapi hit a Taiwanese company’s email system with a Chinese model that researchers believe was DeepSeek. Western tools appear too. 

TeamT5 said a group tracked as Slime22 breached a Taiwanese technology firm’s systems, installed Kali, and directed Claude Code to run lateral movement. Operators bypassed safeguards by claiming to be engineers conducting authorized tests.

Meanwhile, CyCraft traced a 10-person Chinese startup selling intrusion software for 300,000 to 500,000 yuan, or roughly $44,500 to $74,000. At least four hacking groups bought it.  The company also used ChatGPT during an attack.

A spokesperson for OpenAI said the firm is committed to identifying, preventing, and disrupting attempts to abuse its models.

Meanwhile, Chinese groups are not alone in this shift. North Korea’s Kimsuky is also testing local models.

Anthropic reached a broader conclusion in June, finding that AI now handles advanced attack work for hackers who lack the skill to do it themselves.

Subscribe to our YouTube channel to watch leaders and journalists provide expert insights


To read the latest cryptocurrency market analysis from BeInCrypto, click here.

Disclaimer

BeInCrypto is committed to unbiased, transparent reporting. This news article aims to provide accurate, timely information. However, readers are advised to verify facts independently and consult with a professional before making any decisions based on this content. Please note that our Terms and Conditions, Privacy Policy, and Disclaimers have been updated.

Sponsored
Sponsored