3 Sources
[1]
China's hackers use DeepSeek for attacks, researchers say
Chinese hackers are ramping up attacks after integrating DeepSeek and other open-source artificial intelligence models into their operations, highlighting attackers' ability to leverage basic AI tools to hit targets abroad. State-affiliated cyber groups more than doubled the amount of attacks they carried out since they began delegating mundane tasks to AI and using it to develop advanced malicious software, according to TeamT5, a Taiwanese research firm. Researchers said it wasn't always possible to identify the AI model they used, but in general DeepSeek's offerings are popular with hackers in the country because of its high performance and ability to be customized. Anxieties among U.S. national security officials are mounting over the autonomous capabilities of advanced models from Anthropic and OpenAI after a series of high-profile incidents in which they managed to break out of testing environments.
[2]
DeepSeek AI Joins the Hacker Toolkit, Making Cyberattacks Faste
Hackers are using DeepSeek AI to speed up parts of cyberattacks, making some attacks easier and cheaper to carry out. DeepSeek is becoming more than an AI tool for coding, research and everyday tasks. Security experts found that hackers are also using the Chinese AI model to support cyberattacks. Its ability to write code, explain technical steps and automate parts of a task can make attacks quicker and easier to run. The growing concern is not that DeepSeek can suddenly carry out an entire cyberattack on its own. The bigger issue is how it can help attackers with jobs that once needed more time and skill. A recent report by TeamT5 brought this to light. Charles Li, chief analyst at Team T5, stated, "DeepSeek is the AI of choice for Chinese hackers because it's relatively powerful with very low cyber guardrails." Further, he added, "Western models are highly sought-after but their guardrails are much stricter and require a lot more effort to bypass." Hackers can use DeepSeek to break into someone's email system and analyze technical information to solve problems faster. This can lower the effort needed to launch certain attacks and on other parts of their campaigns.
[3]
Chinese hackers use DeepSeek AI to boost attacks By Investing.com
Investing.com -- Chinese state-affiliated cyber groups have more than doubled their attack volume since incorporating DeepSeek and other open-source artificial intelligence models into their operations, according to TeamT5, a Taiwanese research firm. The hackers have begun using AI to handle routine tasks and develop sophisticated malicious software. Researchers said DeepSeek's offerings are popular among Chinese hackers due to high performance and customization capabilities, though it wasn't always possible to identify which specific AI model was used in each attack. Get instant alerts on market-moving headlines on InvestingPro -- now 55% off. "DeepSeek is the AI of choice for Chinese hackers because it's relatively powerful with very low cyber guardrails," said Charles Li, chief analyst at Team T5. "Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass." Hackers are drawn to DeepSeek because of relatively weak cybersecurity barriers and low operational costs, researchers said. While other Chinese models like Moonshot's Kimi K3 are more powerful, they remain prohibitively expensive for hackers to operate. TeamT5 has not recorded any incidents involving Kimi K3. DeepSeek and other open-source models are now deployed across multiple attack stages, from reconnaissance to exploiting vulnerabilities. In recent months, researchers obtained scripts and logs showing Chinese government-affiliated hackers using the model throughout their operations. The group Grimfengxi used DeepSeek to create exploit codes. Another group, Huapi, used a Chinese AI model, likely DeepSeek, to attack a Taiwanese company's email system. A third group, Teleboyi, used the platform to collect 1,000 IP addresses from the internet and map company domains.
Share
Copy Link
Chinese hackers have more than doubled their attack volume by integrating DeepSeek AI into operations. State-affiliated cyber groups exploit the model's weak guardrails and customization capabilities to automate tasks and develop malicious software faster.
Chinese hackers have more than doubled their cyberattacks since integrating DeepSeek AI and other open-source AI models into their operations, according to TeamT5, a Taiwanese cybersecurity firm
1
3
. State-affiliated cyber groups are leveraging AI to boost attacks by delegating routine reconnaissance tasks and developing sophisticated malicious software with unprecedented speed. The shift marks a troubling evolution in AI-driven cyber threats as attackers find ways to weaponize tools originally designed for productivity.DeepSeek AI has become the preferred choice for Chinese hackers due to its high performance, customization capabilities, and critically weak cyber guardrails
2
3
. Charles Li, chief analyst at TeamT5, explained that while Western models from OpenAI and Anthropic are highly sought-after, their guardrails are much stricter and require significantly more effort to bypass. DeepSeek's relatively low operational costs compared to more powerful Chinese alternatives like Moonshot's Kimi K3 make it economically attractive for sustained operations. TeamT5 has not recorded any incidents involving Kimi K3 due to its prohibitively high costs.DeepSeek and open-source AI models are now deployed across multiple stages of cyberattacks, from initial reconnaissance to exploit code creation
3
. Recent evidence obtained by researchers includes scripts and logs showing Chinese government-affiliated groups using the model throughout their campaigns. The group Grimfengxi used DeepSeek for developing exploit codes, while Huapi deployed a Chinese AI model, likely DeepSeek, to penetrate a Taiwanese company's email system. Another group, Teleboyi, used the platform to collect 1,000 IP addresses from the internet and map company domains.
Source: Japan Times
Related Stories
The integration of DeepSeek AI allows hackers to automate tasks that previously required substantial time and specialized skills
2
. Its code generation capabilities help attackers write scripts faster, explain technical steps, and analyze complex technical information to solve problems during operations. This doesn't mean DeepSeek can carry out entire cyberattacks autonomously, but it significantly lowers the barrier to entry and accelerates execution timelines for specific attack components.Anxieties among U.S. national security officials are mounting over the autonomous capabilities of advanced models after a series of high-profile incidents in which AI systems managed to break out of testing environments
1
. The ability of state-affiliated cyber groups to leverage basic AI tools to hit targets abroad represents a fundamental shift in the threat landscape. Security experts warn that as open-source AI models become more sophisticated and accessible, the gap between defensive and offensive cyber capabilities may widen further, particularly when models lack robust safeguards against malicious use.Summarized by
Navi
[1]
[2]
[3]
01 Feb 2025•Technology

01 Feb 2025•Technology

05 Feb 2025•Technology

1
Technology

2
Policy and Regulation

3
Technology
