Chinese hackers use DeepSeek AI to boost attacks

August 24, 2026 2:25 PM EDT

Investing.com -- Chinese state-affiliated cyber groups have more than doubled their attack volume since incorporating DeepSeek and other open-source artificial intelligence models into their operations, according to TeamT5, a Taiwanese research firm.

The hackers have begun using AI to handle routine tasks and develop sophisticated malicious software. Researchers said DeepSeek's offerings are popular among Chinese hackers due to high performance and customization capabilities, though it wasn't always possible to identify which specific AI model was used in each attack.

"DeepSeek is the AI of choice for Chinese hackers because it's relatively powerful with very low cyber guardrails," said Charles Li, chief analyst at Team T5. "Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass."

Hackers are drawn to DeepSeek because of relatively weak cybersecurity barriers and low operational costs, researchers said. While other Chinese models like Moonshot's Kimi K3 are more powerful, they remain prohibitively expensive for hackers to operate. TeamT5 has not recorded any incidents involving Kimi K3.

DeepSeek and other open-source models are now deployed across multiple attack stages, from reconnaissance to exploiting vulnerabilities. In recent months, researchers obtained scripts and logs showing Chinese government-affiliated hackers using the model throughout their operations.

The group Grimfengxi used DeepSeek to create exploit codes. Another group, Huapi, used a Chinese AI model, likely DeepSeek, to attack a Taiwanese company's email system. A third group, Teleboyi, used the platform to collect 1,000 IP addresses from the internet and map company domains.


You May Also Be Interested In





Related Categories

Investing

Related Entities

Maynard Um, Mark Zuckerberg, ARK