HomeMarket News

Chinese Hackers Use DeepSeek AI to Launch Autonomous Cyberattacks

Chinese Hackers Use DeepSeek AI to Launch Autonomous Cyberattacks

In Brief:

  • Chinese state-linked hackers use DeepSeek for reconnaissance, exploit creation, and malware development, doubling attack activity while reducing operational costs.
  • Autonomous agents helped a Chinese-speaking attacker target more than 460 systems while requiring limited human supervision across the extensive campaign.
  • The attackers also used ChatGPT and Claude Code, demonstrating how affordable AI tools can expand complex intrusion capabilities significantly at scale.

 


Chinese state-linked hacking groups are using DeepSeek AI to automate cyberattacks and target more systems with fewer resources. According to Taiwanese cybersecurity firm TeamT5, their attack activity has more than doubled through the integration of artificial intelligence.


These groups now use AI across reconnaissance, vulnerability research, target discovery, malware development, and exploit creation. DeepSeek has become a popular option because it offers capable performance, low operating costs, and relatively weak cybersecurity restrictions.


TeamT5 chief analyst Charles Li identified DeepSeek as the preferred model among several Chinese hacking groups. He linked that preference to the model’s accessibility and limited safeguards against potentially harmful cybersecurity requests.


Consequently, experienced attackers can complete demanding assignments faster without expanding their teams or investing heavily in additional infrastructure. TeamT5 identified several groups that allegedly used artificial intelligence during separate campaigns against companies and institutional targets.


Grimfengxi reportedly used DeepSeek to generate exploit code for systems containing known or newly discovered security weaknesses. Meanwhile, Huapi employed a Chinese AI model while targeting the email infrastructure of a Taiwanese company.


Researchers believe the model was DeepSeek, although available evidence did not provide complete confirmation of its identity. Additionally, Teleboyi used the technology to gather roughly 1,000 internet protocol addresses and map corporate domains. Such information can help attackers identify exposed services, understand organizational networks, and prepare more targeted intrusion attempts.


Also Read: Franklin Templeton Expands Asian Tokenized Fund Access Through HashKey Exchange


DeepSeek Agent Targeted More Than 460 Systems

Research from Palo Alto Networks’ Unit 42 uncovered another Chinese-linked campaign involving DeepSeek and the Hermes Agent framework. A Chinese-speaking attacker used the framework to locate vulnerable machines, obtain exploitation tools, and initiate attacks with limited supervision.


The campaign targeted more than 460 systems, demonstrating how autonomous agents can extend an attacker’s reach across multiple networks. Moreover, AI agents can handle repetitive technical work while human operators manage objectives, select targets, and adjust broader strategies.


Chinese attackers have also adopted Western artificial intelligence models when those platforms provide useful coding or data-processing capabilities. Cybersecurity company CyCraft discovered evidence that a hacking-tool vendor used ChatGPT while attacking a Western think tank.


The attackers compromised an employee’s computer and obtained a locally stored database from the encrypted messaging application Signal. They then used ChatGPT to help develop software intended to decrypt information contained within the stolen database.


TeamT5 also connected the Slime22 hacking group with Anthropic’s Claude Code during a Taiwanese technology company breach. Hackers allegedly presented themselves as cybersecurity engineers, allowing them to bypass safeguards restricting harmful requests. They later used the coding model to support movement across the company’s systems following the initial unauthorized access.


Affordable AI Expands the Scale of Cyber Operations

These cases indicate that attackers do not need the most advanced artificial intelligence models to improve their operational capabilities. Affordable open-source models can automate repetitive assignments and provide technical assistance during several stages of an intrusion.


Hence, skilled hacking groups can investigate more targets while operating with smaller teams and lower infrastructure expenses. The technology also shortens the time required for reconnaissance, vulnerability analysis, exploit preparation, and network mapping.


However, AI does not remove the need for experienced operators who understand security weaknesses and can direct automated tools effectively. Cybersecurity teams now face campaigns combining human expertise with automated systems capable of performing complex technical assignments.


Organizations may therefore require stronger monitoring to detect rapid reconnaissance, automated exploitation attempts, and unusual movement across internal networks. AI-assisted cyberattacks are increasing operational speed and scale while lowering barriers that previously limited sophisticated hacking campaigns.


Also Read: XRP Ledger Operators Urged to Upgrade as Major Amendment Nears Approval