Chinese hackers are using DeepSeek AI to launch autonomous cyberattacks Chinese state-linked hacking groups have more than doubled their attack volume after integrating DeepSeek and other AI models into cyber operations, according to Taiwanese cybersecurity firm TeamT5. DeepSeek is favored for its performance, low cost, and limited security restrictions, enabling automation of reconnaissance, exploit development, and target discovery. Palo Alto Networks' Unit 42 also found a Chinese-speaking attacker using DeepSeek via the Hermes Agent framework to target over 460 systems with limited human involvement. Via cnet.com Chinese hackers are using DeepSeek AI to launch autonomous cyberattacks TeamT5 says Chinese state linked groups have more than doubled attack activity after integrating AI into cyber operations. Chinese state linked hacking groups are increasingly using DeepSeek and other artificial intelligence models to automate cyber operations and increase the scale of their attacks, according to Taiwanese security researchers. Attack volume from the groups has more than doubled since they began using AI for routine tasks and malware development, according to cybersecurity firm TeamT5. Researchers said DeepSeek has become particularly popular because of its performance, low operating costs, and relatively limited cybersecurity restrictions. “DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” TeamT5 chief analyst Charles Li said. Researchers said attackers are using AI throughout different stages of cyber operations, including reconnaissance, vulnerability research, exploit development, and target discovery. TeamT5 identified several groups using the technology. Grimfengxi allegedly used DeepSeek to generate exploit code, while Huapi used a Chinese AI model believed to be DeepSeek in an attack targeting a Taiwanese company’s email system. Another group known as Teleboyi used the technology to collect roughly 1,000 internet protocol addresses and map corporate domains. Separate research from Palo Alto Networks’ Unit 42 recently found a Chinese speaking attacker using DeepSeek through the Hermes Agent framework to identify vulnerable systems, obtain exploit tools, and initiate attacks with limited human involvement. The campaign targeted more than 460 systems. Chinese attackers have also turned to Western AI models. Cybersecurity firm CyCraft found evidence that a company selling hacking tools used ChatGPT while targeting a Western think tank. After compromising an employee’s computer and obtaining a local Signal database, the attackers used the chatbot to help develop software intended to decrypt it. TeamT5 also said a group known as Slime22 used Anthropic’s Claude Code after breaching a Taiwanese technology company. The hackers allegedly presented themselves as cybersecurity engineers to bypass safeguards and used the model to assist with movement through the company’s systems. The findings suggest that sophisticated attackers do not necessarily require the most advanced AI models to significantly increase the speed and scale of cyber operations. DeepSeek and other open source models can already automate tasks that previously required substantial manual work, potentially allowing experienced hacking groups to target more systems with fewer resources. Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy https://cryptobriefing.com/editorial-policy/ .