
Chinese state-linked hacking groups have more than doubled their attack volume since folding the Chinese AI model DeepSeek into their operations. That is the finding of a new analysis by Taiwanese security firm TeamT5, first reported by Bloomberg. The results offer some of the most concrete evidence yet of how much generative AI is lowering the barrier to entry for cyberattacks, and they also highlight that Western models like ChatGPT and Anthropic’s Claude are turning up in such operations too.
Key takeaways
- TeamT5 documents more than double the attack volume among state-linked Chinese hacking groups since they began using AI tools, DeepSeek chief among them.
- DeepSeek is the tool of choice because it is capable, cheap to run, and comes with comparatively weak safety guardrails, according to TeamT5 chief analyst Charles Li.
- The group Grimfengxi used it to generate exploit code, Huapi targeted a Taiwanese company’s email system, and Teleboyi used AI-assisted scanning to map roughly 1,000 IP addresses and corporate domains.
- Western models show up too: a group TeamT5 calls Slime22 reportedly used Anthropic’s Claude Code to move laterally through a Taiwanese tech company’s network.
- A UK AI safety institute confirms that open Chinese models are catching up fast on cyber capability but still lag Western frontier models by several months on fully autonomous attack chains.
Why DeepSeek specifically
The answer is mundane, and that is exactly what makes it unsettling: DeepSeek is good enough, costs little, and is easy to push into doing things ChatGPT or Claude would refuse. TeamT5 chief analyst Charles Li puts it plainly, describing the model as relatively capable while carrying very weak safety guardrails. Western providers lock down their models with extensive filters against obviously malicious requests, but those same restrictions on open models like DeepSeek are either easier to bypass or simply weaker to begin with. Cost matters too: more capable Chinese alternatives like Moonshot’s Kimi K3 are, according to TeamT5, more powerful but too expensive to run at the scale hacking operations require. DeepSeek sits exactly at the intersection of cost, capability, and lax control that makes it attractive.
What the groups are actually doing with it
The cases TeamT5 documented show how varied the use already is. Grimfengxi uses DeepSeek to automatically generate exploit code, meaning code built to target specific vulnerabilities in someone else’s software. Huapi deployed a Chinese AI model, likely also DeepSeek, against a Taiwanese company’s email system. Teleboyi used AI assistance to automate the reconnaissance phase of an attack, collecting roughly 1,000 IP addresses and a map of corporate domains, work that used to take analysts days. Particularly notable is the case of a group called Slime22, which TeamT5 says relied not on a Chinese model but on Anthropic’s Claude Code to move laterally through a Taiwanese tech company’s network after an initial breach, working from one compromised system to the next. That shows the line between open and closed models has, in attackers’ practice, stopped tracking country of origin or vendor and now simply tracks whatever is easiest to get hold of at the moment.
How dangerous is this, really
A UK AI safety institute tempers the alarm on one key point: open models like DeepSeek are catching up quickly on cyber capability, but still lag the most advanced Western models by several months on fully autonomous, multi-step attack chains. What is happening now looks less like a leap into entirely new attack methods and more like a massive efficiency boost for already-known ones. Work that used to require specialized developers or experienced analysts, such as writing exploit code or systematically scanning entire networks for weaknesses, can now partly be handed off to a language model. That lowers the cost per attack and lets even less specialized groups cover more targets in less time, driving up the sheer number of attacks even if the sophistication of any single attack does not necessarily rise.
A pattern that goes beyond China
The finding is hard to confine to a single country or a single vendor. As soon as a model is capable enough and publicly available, it becomes useful to attackers too, regardless of where it was built. The fact that Claude Code itself shows up in a documented attack, echoing other cases of Chinese users working around Anthropic’s usage restrictions, shows that even more tightly guarded Western tools cannot fully insulate themselves from misuse once access becomes available through workarounds. For security teams, the takeaway is straightforward: defense can no longer assume attackers are slowed down by limited resources or skill the way they once were. AI-assisted reconnaissance and code generation are visibly tilting that balance toward attackers, especially for small and midsize companies without large in-house security teams.
What comes next
TeamT5 expects the trend to continue as more capable open models with weak safety guardrails become available. For defenders, the real consequence likely lies less in new specialized techniques than in the need to monitor AI-assisted attack patterns as systematically as classic attack vectors, for instance by flagging unusually fast and broad scanning activity. Responsibility here does not rest with model providers alone: as long as a capable language model is freely available somewhere, it will sooner or later be used for attacks too, no matter how many filters its original developer built in.
