Researchers say Chinese hackers use DeepSeek to carry out attacks Clio

Researchers say Chinese hackers use DeepSeek to carry out attacks

 Clio

Chinese hackers are ramping up their attacks after integrating DeepSeek and other open source AI models into their operations, underscoring the ability of attackers to leverage basic AI tools against foreign targets.

According to Taiwanese research firm TeamT5, the number of attacks carried out by state-affiliated cyber groups has more than doubled since it began delegating daily tasks to artificial intelligence and using it to develop advanced malware. The researchers said it was not always possible to identify the AI ​​models they used, but overall, DeepSeek’s products are popular with hackers in the country for their high performance and ability to be customized.

U.S. national security officials are increasingly concerned about the autonomous capabilities of advanced models from Anthropic PBC and OpenAI after a series of high-profile incidents that successfully breached testing environments.

Researchers say sophisticated Chinese hackers are using much less capable artificial intelligence to expand their activities and achieve breakthroughs. Researchers say that while other models produced in the country are more powerful, including Moonshot’s groundbreaking Kimi K3 model, hackers were attracted to DeepSeek’s relatively lax cybersecurity barriers and lower running costs. They added that they have not documented an incident involving Kimi K3, which they believe would be too costly for hackers to run.

“DeepSeek is the AI ​​of choice for Chinese hackers because it is relatively powerful and has very low network guardrails,” said Charles Li, principal analyst at TeamT5. “Western models are popular, but their guardrails are much stricter and require more effort to bypass.”

DeepSeek did not respond to a request for comment. Neither the Chinese Embassy in Washington nor the Ministry of Foreign Affairs responded to messages seeking comment.

TeamT5 said that along with a combination of other open source models, DeepSeek has been used at multiple stages of an attack to conduct reconnaissance and generate attack vulnerabilities. They say that in recent months they have obtained scripts and logs showing that hackers affiliated with the Chinese government used the model throughout the operation.

A group called Grimfengxi used DeepSeek to create exploitable code. Another group called Huapi used a Chinese artificial intelligence model, which researchers said was likely DeepSeek, to attack the email system of a Taiwanese company. A third company, Teleboyi, uses the platform to collect 1,000 IP addresses from the Internet and map the company’s domain names.

In some cases, Chinese hackers have turned to U.S. artificial intelligence for help. Cybersecurity firm CyCraft said a company that sells hacking software used ChatGPT in attacks on Western think tanks. After obtaining a copy of an employee’s local signals database from an infected computer, the hackers consulted a chatbot to help build a software module designed to decrypt the database, according to screenshots reviewed by Bloomberg News.

An OpenAI spokesperson said the company is committed to identifying, preventing and blocking attempts to abuse its models.

Researchers made the discovery after discovering a public shared drive containing thousands of Chinese-language screenshots taken as recently as February. The images show the workflow of a small startup, made up of about 10 employees, that develops hacking tools for sale. Their software charges between 300,000 yuan ($44,500) and 500,000 yuan ($74,000). Its clients are at least four separate hacking groups, each running their own campaigns. Activities associated with one of these groups overlapped with operations publicly attributed to Mustang Panda, which the U.S. Department of Justice said was supported by the Chinese government.

Anthropic’s tools were also used. TeamT5 says a group called Slime22 successfully used Cloud code to move within the systems of a Taiwanese technology company. After breaking into the company’s system, the organization built its own well-known penetration testing platform, the Kali system, and asked Claude to use it for lateral movement. They added that hackers successfully bypassed cybersecurity guardrails by impersonating engineers to conduct these cybersecurity tests.

Anthropic did not respond to questions seeking comment.

Anthropic has blocked Chinese-controlled companies from offering its services. Last September, Chinese state-backed hackers used Cloud code to conduct autonomous attacks against 30 entities, including large technology companies, financial institutions, chemical manufacturers, and government agencies. They tricked the tool into trying to infiltrate these entities, the company said, adding that it marked the first documented case of a large-scale cyberattack being executed without significant human intervention.

Photo credit: Victor J. Blue/Bloomberg

Related:

Copyright 2026 Bloomberg.

theme
Internet China

interested in network?

Get automatic alerts on this topic.

Leave a Reply

Your email address will not be published. Required fields are marked *