Chinese state hackers are using DeepSeek to double their attack volume, researchers say

Chinese state-affiliated hackers have more than doubled their attack output since they started using DeepSeek and other open-source AI models to automate the repetitive parts of their operations. That’s the headline finding from TeamT5, a Taiwanese research firm that has been tracking these groups closely, as reported by The Straits Times. And if you were hoping that AI safety measures would slow this kind of abuse down, the findings suggest the opposite is happening.

TeamT5 researchers say DeepSeek is the model of choice for these groups, not because it’s the most powerful AI available in China, but because it has weak cybersecurity guardrails and costs very little to run. “Western models are highly sought after, but their guardrails are much stricter and require a lot more effort to bypass,” said Charles Li, chief analyst at TeamT5. So while American national security officials spend their time worrying about what frontier models from OpenAI and Anthropic might do autonomously, experienced threat actors are already getting real results with cheaper, less restricted alternatives.

The researchers documented several specific hacking groups using AI across multiple stages of attacks. A group called Grimfengxi used DeepSeek to generate exploit code. Huapi used what researchers believe was DeepSeek to target the email system of a Taiwanese company. A third group, Teleboyi, used the platform to collect 1,000 IP addresses and map a target company’s network. In each case, the AI wasn’t doing anything miraculous. It was doing the boring, time-consuming groundwork that previously slowed attackers down.

But it wasn’t only Chinese-made AI involved. CyCraft, another cybersecurity firm, found that a company selling hacking tools used ChatGPT during an attack on a Western think-tank. After stealing a copy of an employee’s Signal database from a compromised device, the hackers asked the chatbot how to decrypt it. OpenAI said it is “committed to identifying, preventing and disrupting” attempts to misuse its models. That commitment clearly has limits.

Anthropic’s Claude Code also appeared in the findings. A group called Slime22 used it to move laterally inside a Taiwanese technology company’s systems after gaining access. They got around Claude’s restrictions by pretending to be a security engineer conducting penetration tests. Anthropic had previously disclosed, in 2025, that Chinese state-backed hackers used Claude Code to autonomously attack 30 entities including tech companies, financial institutions, and government agencies. That was described at the time as the first documented large-scale cyberattack executed without substantial human involvement.

The broader picture here is concerning for anyone thinking AI safety guardrails are a reliable defense. Researchers also found a public shared drive containing thousands of Chinese-language screenshots documenting the workflow of a small start-up, around 10 employees, building and selling hacking tools for between 300,000 and 500,000 yuan per piece. Their customers included at least four separate hacking groups, one of which overlaps with Mustang Panda, a group the US Justice Department says is backed by the Chinese government.

What this really shows is a gap between where the AI safety conversation is focused and where the actual risk is landing. The concern in Washington is about powerful autonomous models breaking out of test environments. The reality on the ground is that mid-tier, low-cost, lightly restricted models are already being used to scale up state-sponsored attacks. That’s a much harder problem to solve with guardrails alone.