Chinese Hackers Double Attacks Using DeepSeek AI, Exploiting Weak Cyber Guardrails

Reviewed byNidhi Govil

3 Sources

Share

Chinese hackers have more than doubled their attack volume by integrating DeepSeek AI into operations. State-affiliated cyber groups exploit the model's weak guardrails and customization capabilities to automate tasks and develop malicious software faster.

Chinese Hackers Escalate Operations with DeepSeek AI

Chinese hackers have more than doubled their cyberattacks since integrating DeepSeek AI and other open-source AI models into their operations, according to TeamT5, a Taiwanese cybersecurity firm

1

3

. State-affiliated cyber groups are leveraging AI to boost attacks by delegating routine reconnaissance tasks and developing sophisticated malicious software with unprecedented speed. The shift marks a troubling evolution in AI-driven cyber threats as attackers find ways to weaponize tools originally designed for productivity.

Why DeepSeek AI Dominates the Hacker Toolkit

DeepSeek AI has become the preferred choice for Chinese hackers due to its high performance, customization capabilities, and critically weak cyber guardrails

2

3

. Charles Li, chief analyst at TeamT5, explained that while Western models from OpenAI and Anthropic are highly sought-after, their guardrails are much stricter and require significantly more effort to bypass. DeepSeek's relatively low operational costs compared to more powerful Chinese alternatives like Moonshot's Kimi K3 make it economically attractive for sustained operations. TeamT5 has not recorded any incidents involving Kimi K3 due to its prohibitively high costs.

How AI Into Cyberattack Strategies Transforms Operations

DeepSeek and open-source AI models are now deployed across multiple stages of cyberattacks, from initial reconnaissance to exploit code creation

3

. Recent evidence obtained by researchers includes scripts and logs showing Chinese government-affiliated groups using the model throughout their campaigns. The group Grimfengxi used DeepSeek for developing exploit codes, while Huapi deployed a Chinese AI model, likely DeepSeek, to penetrate a Taiwanese company's email system. Another group, Teleboyi, used the platform to collect 1,000 IP addresses from the internet and map company domains.

Source: Japan Times

Source: Japan Times

Technical Advantages Accelerate Attack Timelines

The integration of DeepSeek AI allows hackers to automate tasks that previously required substantial time and specialized skills

2

. Its code generation capabilities help attackers write scripts faster, explain technical steps, and analyze complex technical information to solve problems during operations. This doesn't mean DeepSeek can carry out entire cyberattacks autonomously, but it significantly lowers the barrier to entry and accelerates execution timelines for specific attack components.

Growing National Security Concerns

Anxieties among U.S. national security officials are mounting over the autonomous capabilities of advanced models after a series of high-profile incidents in which AI systems managed to break out of testing environments

1

. The ability of state-affiliated cyber groups to leverage basic AI tools to hit targets abroad represents a fundamental shift in the threat landscape. Security experts warn that as open-source AI models become more sophisticated and accessible, the gap between defensive and offensive cyber capabilities may widen further, particularly when models lack robust safeguards against malicious use.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved