logo-darklogo-darklogo-darklogo-dark
  • Tool Categories
    • 🎨Art & Creative Design505
    • 🏢Business Management644
    • 💻Coding & Development514
    • 👮Detection83
    • 🧠General Use728
    • 🏥Health & Wellness55
    • 📷Image & Photo Analysis100
    • 🖼️Image Generation & Editing618
    • 📐Interior & Architectural Design37
    • 🎓Learning & Education483
    • ⚖️Legal & Finance90
    • 🎭Lifestyle & Entertainment236
    • 📢Marketing & Advertising627
    • 🎧Music & Audio138
    • 👔Office & Workplace1,014
    • 🔬Research & Data Analysis373
    • 👥Social Media245
    • 🎥Video Generation & Editing426
    • 👧🏻Virtual Companion135
    • 🎤Voice Generation & Editing381
    • ✍️Writing & Editing808
    • All Categories
    • AI Use Cases
  • News
  • Events
    • Academic Conferences
    • Developer Conferences
    • Expos / Trade Shows
    • Industry Summits
    • Workshops / Training
    • All Events
    • Past Events
  • Saved Tools
  • Suggest a Tool
✕
Home › News › Chinese state hackers are using DeepSeek to double their attack output

Chinese state hackers are using DeepSeek to double their attack output

August 25, 2026
Chinese state hackers are using DeepSeek to double their attack output

The threat isn’t some theoretical future scenario where superintelligent AI runs cyberattacks autonomously. It’s already happening, and the tool of choice is a cheap, customizable Chinese model with notoriously weak safety filters. According to The Straits Times, Chinese state-affiliated hacking groups have more than doubled their attack volume after integrating DeepSeek and other open-source AI models into their workflows.

The findings come from TeamT5, a Taiwanese cybersecurity research firm that has been tracking Chinese hacking operations closely. Their researchers obtained scripts, logs, and screenshots showing DeepSeek being used at multiple stages of attacks, from initial reconnaissance and IP mapping to writing exploit code and moving laterally through compromised systems. The targets have included Taiwanese companies, Western think-tanks, tech firms, financial institutions, and government agencies.

What makes this significant is not that AI is being used by hackers. That’s been expected for years. What’s notable is which AI they’re choosing, and why. Charles Li, chief analyst at TeamT5, put it plainly: DeepSeek is the model of choice because it’s powerful enough to be useful, cheap to run, and has far weaker cybersecurity guardrails than Western alternatives. Getting ChatGPT or Claude to help write malware requires effort. Getting DeepSeek to do the same is, apparently, much easier.

The research identified several distinct hacking groups using DeepSeek in different ways. A group called Grimfengxi used it to generate exploit code. Huapi used a Chinese model, likely DeepSeek, to attack the email system of a Taiwanese company. Teleboyi used it to collect and map 1,000 IP addresses. One of these groups has operational overlap with Mustang Panda, a hacking collective the US Justice Department says is backed by the Chinese government.

But DeepSeek isn’t the only model showing up in these operations. Anthropic’s Claude Code was used by a group called Slime22 to conduct lateral movement inside a Taiwanese tech company’s systems after the hackers posed as penetration testers to bypass safety checks. And in a separate incident tracked by CyCraft, a hacking software vendor used ChatGPT to help decrypt a Signal database pulled from a compromised machine. OpenAI said it’s committed to blocking such abuse. Anthropic noted it had already banned services to Chinese-controlled companies.

This research matters because it reframes the AI safety conversation. While US officials are focused on whether frontier models from Anthropic or OpenAI might autonomously break out of testing environments, state-sponsored hackers are getting real operational value out of much less capable, far cheaper tools. The barrier to scaling up attacks just dropped significantly. A small team of roughly 10 people, selling hacking tools for between 300,000 and 500,000 yuan per package, was already running a multi-client operation serving at least four separate hacking groups.

  • DeepSeek is preferred for its low cost, customizability, and weak content filters
  • Claude Code was used for lateral movement inside compromised networks
  • ChatGPT was consulted to help decrypt a stolen Signal database
  • One client group overlaps with Mustang Panda, a Chinese government-linked operation

For security teams and AI companies alike, the takeaway is uncomfortable. Stricter guardrails on Western models may be pushing attackers toward open-source alternatives where those guardrails simply don’t exist. That’s not an argument against safety controls. But it does mean that tightening rules at Anthropic and OpenAI has a limited effect when DeepSeek is freely available and eager to help.

Share

Related news

Stability AI raises $76M from Sony, Universal, and Warner in a bet on creative AI
August 25, 2026

Stability AI raises $76M from Sony, Universal, and Warner in a bet on creative AI


Read more
Claude’s memory now spans chats and Cowork sessions, with a new sensitive topics toggle
August 25, 2026

Claude’s memory now spans chats and Cowork sessions, with a new sensitive topics toggle


Read more
OpenAI’s Jalapeño chip beats Nvidia Blackwell on inference benchmarks, but the real test comes later
August 25, 2026

OpenAI’s Jalapeño chip beats Nvidia Blackwell on inference benchmarks, but the real test comes later


Read more

Recent Posts

  • Stability AI raises $76M from Sony, Universal, and Warner in a bet on creative AI
  • Claude’s memory now spans chats and Cowork sessions, with a new sensitive topics toggle
  • OpenAI’s Jalapeño chip beats Nvidia Blackwell on inference benchmarks, but the real test comes later
  • Chinese state hackers are using DeepSeek to double their attack output
  • Anthropic’s most powerful model is losing the price war before the company even goes public
Best AI Tools

Discover the best AI tools for any use case

Explore
  • Tool Categories
  • AI Use Cases
  • AI Events
  • AI News
  • Saved Tools
Company
  • About Us
  • Contact Us
  • Media & Partnerships
  • Suggest a Tool
Legal
  • Privacy Policy
  • Terms of Service
Copyright © 2026 Best AI Tools 415 Mission Street, 37th Floor, San Francisco, CA 94105