{"slug": "chinese-state-hackers-doubled-their-attack-volume-using-deepseek-ai", "title": "Chinese State Hackers Doubled Their Attack Volume Using DeepSeek AI", "summary": "Chinese state-linked hacking groups have more than doubled their attack volume since adopting DeepSeek and other open-source AI models, according to a Bloomberg report published August 24 citing TeamT5's findings. Palo Alto Networks' Unit 42 separately documented a Chinese-speaking actor who wired DeepSeek into the Hermes Agent framework, enabling autonomous reconnaissance and attacks on over 460 targets, with confirmed impact on three Citrix NetScaler endpoints via CVE-2026-3055 and 11 Marimo notebook endpoints via CVE-2026-39987.", "body_md": "*Chinese state-linked hackers are using DeepSeek to make attacks faster and cheaper, and the useful question now is whether your patching rhythm can keep up.*\n\nYou don't need a nation-state budget to scale a cyberattack anymore. You need a model that will answer the wrong questions cheaply. Bloomberg reported on August 24 that Chinese state-affiliated hacking groups have more than doubled their attack volume since they started handing routine work, and some more advanced tasks, to DeepSeek and other open-source AI models.\n\n\"DeepSeek is the AI of choice for Chinese hackers because it's relatively powerful with very low cyber guardrails,\" Charles Li, TeamT5's chief analyst, told Bloomberg. That's the story in one line. It isn't that DeepSeek is the only model that can help an attacker. Bloomberg's report said Moonshot's Kimi K3 is considered more powerful, but TeamT5 hasn't recorded an incident tied to it, in part because running it is too expensive for the attackers the firm tracks.\n\nThe examples are plain enough. According to Bloomberg's account of TeamT5's findings, Grimfengxi used DeepSeek to create exploit code. Huapi used a Chinese AI model, likely DeepSeek, to attack a Taiwanese company's email system. Teleboyi used the platform to collect 1,000 IP addresses from the internet and map company domains. That's not some vague future risk. That's reconnaissance, exploit work and target mapping being pulled into the same cheap workflow.\n\n## A lone hacker got too close\n\nPalo Alto Networks' Unit 42 published a separate report on July 30 that makes the problem sharper. It described a Chinese-speaking actor using the aliases knaithe and KnYuan, based on public GitHub activity and other evidence, who wired DeepSeek into the open-source Hermes Agent framework and controlled it through Telegram. The setup let the model enumerate targets, search for exploit tools and start attacks without a human stepping through each command.\n\n[The EU's AI deepfake labeling law takes effect Sunday with a 38-person enforcement squad already watching](https://startupfortune.com/the-eus-ai-deepfake-labeling-law-takes-effect-sunday-with-a-38-person-enforcement-squad-already-watching/)\n\nArticle 50 of the EU AI Act takes effect August 2, 2026, requiring AI labels on deepfakes, chatbots, and public-interest text across the EU. The European Commission finalized its guidance on July 20 and has expanded its AI Office by 38 staff to monitor firms including OpenAI and DeepSeek, with fines reaching €15 million or 3% of global turnover... - [EU AI Act deepfake labeling requirements](https://startupfortune.com/the-eus-ai-deepfake-labeling-law-takes-effect-sunday-with-a-38-person-enforcement-squad-already-watching/) - [AI disclosure law enforcement Europe 2026](https://startupfortune.com/the-eus-ai-deepfake-labeling-law-takes-effect-sunday-with-a-38-person-enforcement-squad-already-watching/)\n\nThe autonomous part didn't produce the clean Hollywood version of an AI break-in. Good. That detail matters. Unit 42 said the actor attempted to exploit more than 460 targets using a mix of autonomous and manual techniques, and confirmed impact came from three Citrix NetScaler targets hit through CVE-2026-3055 and 11 Marimo notebook endpoints hit through CVE-2026-39987. Some AI-led attempts failed because the targets required authentication or had restrictive settings.\n\nStill, don't take much comfort from that. Unit 42's Andy Piazza wrote that the campaign showed a working autonomous offensive capability, even with limited impact, and that the attacker was refining tool configurations, proxy infrastructure and attack cycles. The weak version is already useful. It scanned, narrowed targets and saved the operator time. Attackers don't need the model to be brilliant if it can make the dull work nearly free.\n\nPut TeamT5 and Unit 42 together and you get an uncomfortable picture. One report shows state-linked crews using AI across established operations. The other shows a single operator using DeepSeek and Hermes Agent to push through much of an attack chain with limited human input. Neither story depends on a brand-new exploit. Both depend on old security pressure getting faster.\n\n## Guardrails are now an operational control\n\nThe refusal gap is the real issue, not DeepSeek's raw intelligence. Western labs such as OpenAI, Anthropic and Google have spent years training their models to refuse obvious cyber abuse, and attackers still test them. Unit 42 found limited use of Claude Code for connectivity testing and proxy validation, and signs of Codex activity in exploit development directories, though it said Codex chat logs weren't recovered. DeepSeek, by contrast, was the reasoning engine for the attack phase Unit 42 reconstructed.\n\nDeepSeek's own history adds a useful bit of irony. In January 2025, the company said large-scale malicious attacks on its services forced it to limit new registrations, as Axios and other outlets reported at the time. Now TeamT5 says Chinese state-linked hackers are choosing DeepSeek because it is cheap, capable and easier to push into cyber work than guarded Western systems. Frankly, that should end the lazy argument that safety limits are just paperwork for lawyers.\n\nFor companies outside China, the takeaway is practical. If attack volume roughly doubles, the old patch calendar starts to look reckless. A team that waits weeks to fix exposed systems is now competing against operators who can ask a model to collect domains, sort targets and draft exploit code while they sleep. Unit 42's Citrix and Marimo findings are the kind of dry details you should care about: known flaws, exposed systems, real compromise. The next breach may not come from a smarter attacker. It may come from a faster one.\n\n**Also read:** [Pew Research Finds a Third of Web Pages Written Since ChatGPT Show AI Signs](https://startupfortune.com/pew-research-finds-a-third-of-web-pages-written-since-chatgpt-show-ai-signs/) • [TCS Will Buy Porsche's MHP Consulting Unit for $373 Million](https://startupfortune.com/tcs-will-buy-porsches-mhp-consulting-unit-for-373-million/) • [Visa and Mastercard Join 26 Firms to Set Rules for AI Agent Payments](https://startupfortune.com/visa-and-mastercard-join-26-firms-to-set-rules-for-ai-agent-payments/)\n\n[Washington threatens to sanction Chinese AI firms over distillation theft as Beijing fires back](https://startupfortune.com/washington-threatens-to-sanction-chinese-ai-firms-over-distillation-theft-as-beijing-fires-back/)\n\nUS Treasury Secretary Scott Bessent threatened sanctions and Entity List blacklisting against Chinese AI firms over industrial-scale distillation campaigns, citing forensic evidence of American model watermarks inside Chinese products. China's commerce ministry called it 'AI hegemonism' Monday and threatened countermeasures, pointing out that US... - [how to use Chinese AI models](https://startupfortune.com/washington-threatens-to-sanction-chinese-ai-firms-over-distillation-theft-as-beijing-fires-back/) - [AI sanctions China trade war](https://startupfortune.com/washington-threatens-to-sanction-chinese-ai-firms-over-distillation-theft-as-beijing-fires-back/)", "url": "https://wpnews.pro/news/chinese-state-hackers-doubled-their-attack-volume-using-deepseek-ai", "canonical_source": "https://startupfortune.com/chinese-state-hackers-doubled-their-attack-volume-using-deepseek-ai/", "published_at": "2026-08-25 01:40:15+00:00", "updated_at": "2026-08-25 02:12:48.730248+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy"], "entities": ["DeepSeek", "Bloomberg", "TeamT5", "Charles Li", "Moonshot", "Kimi K3", "Palo Alto Networks", "Unit 42"], "alternates": {"html": "https://wpnews.pro/news/chinese-state-hackers-doubled-their-attack-volume-using-deepseek-ai", "markdown": "https://wpnews.pro/news/chinese-state-hackers-doubled-their-attack-volume-using-deepseek-ai.md", "text": "https://wpnews.pro/news/chinese-state-hackers-doubled-their-attack-volume-using-deepseek-ai.txt", "jsonld": "https://wpnews.pro/news/chinese-state-hackers-doubled-their-attack-volume-using-deepseek-ai.jsonld"}}