Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > Chinese Hackers Use DeepSeek to Scale Up Cyberattacks, Researchers Say

Chinese Hackers Use DeepSeek to Scale Up Cyberattacks, Researchers Say

By: Morgan Cipher Senior Privacy Journalist

Last updated: August 27, 2026

Human Written
Chinese Hackers Use DeepSeek to Scale Up Cyberattacks, Researchers Say
  • TeamT5 says the attack activity of Chinese state-linked groups more than doubled after they started using AI for routine work.

  • DeepSeek is popular because it is capable, cheap to run and has fewer cyber safety limits.

  • Hackers are using AI for target research, exploit code, and other jobs across the attack process.

Chinese state-linked hacker groups have increased their attack volume by over 100% since AI became part of routine work and malware creation, according to Taiwanese security research firm TeamT5.

The finding shows how cheap AI can change cyber attacks. Hackers can use it to handle work that once took more time.

DeepSeek stands out among the tools TeamT5 has tracked. Researchers say Chinese hackers favor it because it is capable, flexible, and has weak cyber safety limits.

DeepSeek Offers a Cheap Way to Scale Attacks

TeamT5 chief analyst Charles Li said DeepSeek has become a favored AI tool among Chinese hackers. He said its low cyber safety limits make it easier to use for harmful tasks.

Western AI tools can also help attackers. Yet their safety systems often block hacking requests. Attackers may then spend more time getting around those controls.

Cost also matters. TeamT5 said it has not recorded an attack involving Moonshot’s Kimi K3 model. Researchers view Kimi K3 as more capable, but say its higher cost makes it less useful for hackers working at scale.

Hackers Use AI Across Several Attack Stages

TeamT5 linked three Chinese state-linked groups to specific uses of AI. Grimfengxi used DeepSeek to write code to exploit software flaws. Huapi used a Chinese AI agent, likely DeepSeek, against the email system of a Taiwanese company.

Teleboyi used the platform for target research. It collected about 1,000 IP addresses and matched them to company domains. That gave the attackers a wider view of possible targets.

These cases show how AI can take over repetitive work. A human hacker can spend hours searching for systems and sorting data. AI can handle much of that work faster.

TeamT5 said researchers cannot always identify the specific model used in an attack. Still, recent scripts and logs show AI appearing in several parts of Chinese hacking operations.

The Increase in Attack Scale is a Major Concern 

Attackers need to identify targets, study systems, develop code, and then decide where to focus and how much effort to apply. AI can help cut down the time spent on some of these processes.

This does not mean that AI can completely automate hackers’ work. AI models are fallible and could create poor code. Humans are still required to control many operations. However, even a little increase matters, since attackers repeat the same processes for every target.

Fortinet’s 2026 report found global ransomware victims surged 389% year over year to 7,831, with manufacturing, business services, and retail hit hardest. The report links the rise to AI-powered tools that help attackers exploit vulnerabilities within 24-48 hours.

TeamT5’s findings also need some context. Public reporting doesn’t provide enough details about the period under investigation or the exact number of attacks behind the large figure.

Therefore, there is no proof that the only reason for the increase is the usage of AI technology. An increase in targets, campaigns or increased visibility of the threats could influence the result. All we see now is the correlation between AI use and an increased volume of activity among cybercrime groups that TeamT5’s study captured.

Taiwan Remains a Key Target

The findings matter especially for Taiwan, which faces frequent cyber activity linked to China. TeamT5 tracked more than 510 APT operations across 67 countries in 2025. It recorded 173 attacks against Taiwan.

The firm says Taiwan can act as an early warning point for changes in Chinese hacking methods. It has tracked attacks against key infrastructure and supplier networks.

The firm has seen Chinese groups target edge devices, supply chains and trusted services. It has also observed attackers using compromised devices to hide their activity and move through networks.

AI adds another layer to that threat. If attackers can automate more research and code work, they can test more targets without adding the same number of operators.

Western AI Tools are Also Part of the Picture

The TeamT5 research does not show that Chinese hackers rely only on DeepSeek; TeamT5 said one group called Slime22 used Claude Code, Anthropic’s AI model, after gaining access to a Taiwanese technology company.

The group posed as an engineer carrying out approved security tests and used Claude Code to help move through the network. The case shows why AI safety controls matter, but also why they are not a full defense. Attackers can work around limits.

CyCraft also found a Chinese hacking software company using ChatGPT during an attack on a Western research group. The company used the tool to help build software linked to decoding a stolen Signal database.

TeamT5’s wider research also points to a growing Chinese hacking ecosystem. Its 2025 assessment described a mix of state direction, private contractors and specialist vendors. That model can spread hacking skills and tools across many groups.

Cheap AI could Make the Threat Harder to Contain

The key finding may not be DeepSeek itself. It is how attackers use cheap AI to increase their workload.

A model does not need to run an entire attack to have an effect. If it speeds up target research, code writing, or data analysis, human operators can focus on harder decisions. That can let the same team run more campaigns at once.

For defenders, security teams cannot focus only on the models attackers use. They also need to watch for changes in attack speed and behavior. AI can perform much of that work faster and repeat it across many targets. That changes the economics of cyberattacks.

TeamT5’s research suggests that shift is already happening. Cheap AI is giving Chinese state-linked groups a way to do more work with the same number of people. DeepSeek does not need to be the world’s most advanced AI model. It only needs to be capable enough, cheap enough, and easy enough to use.

Share this article

About the Author

Morgan Cipher

Morgan Cipher

Senior Privacy Journalist

Morgan combines a journalist’s curiosity with a security specialist’s precision. His reporting on data breaches, privacy laws, and encryption tech has been featured in several tech publications. At TorWire, he focuses on real-world threats and how to counter them, always with an eye on what’s next in digital privacy.

Comments (0)

No comments.