Chinese Hackers Leverage DeepSeek to Scale Up Cyberattacks

Nashnova编辑部
Published todayAbout 10 min read

Taiwan's TeamT5 reports that Chinese state-linked hacking groups more than doubled their attack frequency after integrating DeepSeek into their workflows — open-source AI is driving down both the cost and the barrier to cyberattacks.

01

Why DeepSeek, specifically?

The logic is straightforward: adequate performance, near-zero safety guardrails, and low operating cost.
This means → DeepSeek's weak defenses — a liability for ordinary users — are its core selling point for hackers.
Western models like ChatGPT and Claude are more capable, but their strict guardrails take extra effort to bypass. Hackers optimize for return on effort.
Moonshot AI's Kimi K3 is stronger still, but too expensive to run. No attack involving Kimi K3 has been recorded so far.
02

How exactly are hackers using it?

DeepSeek has been embedded across multiple stages of the attack chain: reconnaissance, exploit-code generation, and target-information gathering.
Specific cases: "Grimfengxi" used DeepSeek to generate exploit code. "Huapi" used a Chinese AI model — very likely DeepSeek — to attack a Taiwanese company's email system.
"Teleboyi" used the platform to harvest 1,000 IP addresses from the internet and map a target company's domain.
In plain terms = work that hackers once did manually, script by script, now runs through AI — doubling speed and scale.
03

Are Western AI tools any safer?

Not really — some Chinese hackers use ChatGPT and Claude too.
Cybersecurity firm CyCraft disclosed that a company selling hacking software used ChatGPT to build a decryption module during an attack on a Western think tank. The target: a local copy of an employee's Signal database stolen from a compromised computer.
More alarming is Anthropic's case: the hacking group "Slime22" used Claude Code to move laterally inside a Taiwanese tech company's systems — by posing as an engineer running a security test, bypassing Claude's guardrails.
This reflects a harder truth: even heavily guarded Western models are not invulnerable to experienced attackers.
04

What supply chain sits behind this?

Researchers found a publicly shared cloud drive containing thousands of Chinese-language screenshots — revealing a commercialized supply chain for hacking tools.
A startup of roughly 10 people was developing and selling hacking tools, priced at ¥300,000–500,000 (roughly $44,500–$74,000), to at least four separate hacking groups.
One of those client groups' activities overlap with "Mustang Panda" — an operation the U.S. Department of Justice has attributed to the Chinese government.
In plain terms = cyberattacks are no longer just a state activity. They now run on a "developer → distributor → customer" business model.
05

What does this mean for defenders?

Open-source AI models keep lowering the attack barrier. Attacks are becoming cheaper, larger in scale, and faster.
This means → enterprises and government agencies no longer face a small elite of skilled hackers. They face a much larger pool of mid-level attackers now "armed" by AI tools.
Anthropic disclosed a landmark case last year: Chinese state-backed hackers used Claude Code to autonomously attack 30 entities — classified as the first documented large-scale cyberattack requiring no human intervention.
How to counter low-cost, AI-enabled attacks at scale is now the most pressing question in cybersecurity.

Content is for reference only, not financial advice.