{"slug": "deepseek-ai-of-choice-for-hackers-who-use-it-to-boost-attacks-say-researchers", "title": "Deepseek ‘AI of choice’ for hackers, who use it to boost attacks, say researchers", "summary": "Chinese hackers have more than doubled their attacks after integrating DeepSeek and other open-source AI models into their operations, according to TeamT5, a Taiwanese research firm. DeepSeek is the 'AI of choice' for these hackers because it is 'relatively powerful with very low cyber guardrails,' said Charles Li, chief analyst at TeamT5. The hackers use the models for tasks such as reconnaissance, creating exploit codes, and mapping company domains, with some also turning to American AI like ChatGPT and Claude Code.", "body_md": "# Deepseek ‘AI of choice’ for hackers, who use it to boost attacks, say researchers\n\nIts offerings are ‘relatively powerful with very low cyber guardrails’, says a research firm\n\n[HONG KONG] Chinese hackers are ramping up attacks after integrating DeepSeek and other open-source artificial intelligence models into their operations, highlighting attackers’ ability to leverage basic AI tools to hit targets abroad.\n\nState-affiliated cyber groups more than doubled the amount of attacks they carried out since they began delegating mundane tasks to AI and using it to develop advanced malicious software, according to TeamT5, a Taiwanese research firm.\n\nResearchers said it was not always possible to identify the AI model they used, but in general DeepSeek’s offerings are popular with hackers in the country because of its high performance and ability to be customised.\n\nAnxieties among US national security officials are mounting over the autonomous capabilities of advanced models from Anthropic and OpenAI after a series of high-profile incidents in which they managed to break out of testing environments.\n\nResearchers say experienced Chinese hackers are using far less capable AI to scale up their activities and achieve breakthroughs.\n\nWhile other models produced in the country are more powerful – including Moonshot’s breakout Kimi K3 model – hackers are drawn to DeepSeek’s relatively lax cybersecurity barriers and low cost of running, researchers said.\n\nThey added that they had yet to record an incident involving Kimi K3, which they believe is prohibitively expensive for hackers to run.\n\n“DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” said Charles Li, chief analyst at TeamT5.\n\n“Western models are highly sought after but their guardrails are much more strict and require a lot more effort to bypass.”\n\nDeepSeek did not respond to a request for comment. Neither China’s Embassy in Washington nor its Ministry of Foreign Affairs immediately responded to messages seeking comment.\n\nAlong with a mix of other open-source models, DeepSeek has been adopted throughout multiple stages of an attack, conducting reconnaissance and generating means of attacking vulnerabilities, TeamT5 said.\n\nThey said in recent months they have obtained scripts and logs showing the model being used by hackers affiliated with the Chinese government throughout their operations.\n\nA group known as Grimfengxi used DeepSeek to create exploit codes.\n\nAnother group, called Huapi, used a Chinese AI model, which researchers said was likely DeepSeek, to attack an email system of a Taiwanese company.\n\nA third, known as Teleboyi, used the platform to collect 1,000 IP addresses from the internet and map a company’s domains.\n\nIn some cases, Chinese hackers turned to American AI for help. The cybersecurity firm CyCraft said a company that sells hacking software used ChatGPT during an attack on a Western think tank.\n\nAfter obtaining a copy of an employee’s local Signal database from a compromised computer, the hackers consulted the chatbot to help build a software module designed to decrypt it, according to screenshots reviewed by Bloomberg News.\n\nOpenAI did not answer questions seeking comment on the matter.\n\nResearchers made the discovery after finding a public shared drive with thousands of Chinese-language screenshots taken as recently as February.\n\nThe images show the workflow of a small startup comprising about 10 employees developing hacking tools for sale.\n\nThey charged between 300,000 yuan (US$44,500) to 500,000 yuan for their software.\n\nIts customers were at least four separate hacking groups, each running their own campaigns. Activity linked to one of the groups overlaps with operations publicly attributed to Mustang Panda, which the US Justice Department says is backed by the Chinese government.\n\nAnthropic’s tools have also been used. A group known as Slime22 managed to use Claude Code to move around inside the systems of a Taiwanese technology company, TeamT5 said.\n\nAfter breaching the company’s systems the group set up its own system of Kali, a famous penetration testing platform, and asked Claude to use it to conduct lateral movements.\n\nHackers managed to bypass cybersecurity guardrails by posing as an engineer carrying out those cybersecurity tests, they added.\n\nAnthropic did not answer questions seeking comment.\n\nAnthropic has blocked its services from Chinese-controlled companies.\n\nIn 2025, it said Chinese state-backed hackers had used Claude Code in September to autonomously carry out attacks on 30 entities including large tech companies, financial institutions, chemical manufacturers and government agencies.\n\nThey tricked the tool into attempting to infiltrate the entities, the company said, adding it marked the first documented case of a large-scale cyberattack executed without substantial human intervention. BLOOMBERG\n\nDecoding Asia newsletter: your guide to navigating Asia in a new global order. Sign up here to get Decoding Asia newsletter. Delivered to your inbox. Free.\n\nShare with us your feedback on BT's products and services\n\n[TRENDING NOW](/pulse?ref=trending-now)\n\nUOB v Lippo Marina Collection: Court quadruples damages awarded to bank to S$76.1 million\n\nNDR 2026: Childcare leave salary caps still leave gaps for higher-income parents\n\nHow BYD disrupted Singapore’s car market – and why the strategy is turning on itself\n\nWhen every phone becomes a satellite phone, what happens to Asia’s telcos?", "url": "https://wpnews.pro/news/deepseek-ai-of-choice-for-hackers-who-use-it-to-boost-attacks-say-researchers", "canonical_source": "https://www.businesstimes.com.sg/international/deepseek-ai-choice-hackers-who-use-it-boost-attacks-say-researchers", "published_at": "2026-08-25 01:56:51+00:00", "updated_at": "2026-08-25 02:14:00.809702+00:00", "lang": "en", "topics": ["artificial-intelligence", "ai-safety", "ai-policy"], "entities": ["DeepSeek", "TeamT5", "Charles Li", "Moonshot", "Kimi K3", "CyCraft", "OpenAI", "Anthropic"], "alternates": {"html": "https://wpnews.pro/news/deepseek-ai-of-choice-for-hackers-who-use-it-to-boost-attacks-say-researchers", "markdown": "https://wpnews.pro/news/deepseek-ai-of-choice-for-hackers-who-use-it-to-boost-attacks-say-researchers.md", "text": "https://wpnews.pro/news/deepseek-ai-of-choice-for-hackers-who-use-it-to-boost-attacks-say-researchers.txt", "jsonld": "https://wpnews.pro/news/deepseek-ai-of-choice-for-hackers-who-use-it-to-boost-attacks-say-researchers.jsonld"}}