Chinese Hackers Turn to DeepSeek and Other AI Tools as Cyberattack Volume More Than Doubles: Report

AI Cybersecurity Threat: Artificial intelligence is increasingly being incorporated into cyber operations, and a new report suggests China-linked hacking groups are using tools including DeepSeek to automate parts of their campaigns. Taiwanese cybersecurity firm TeamT5 says state-affiliated groups have more than doubled their attack volume since beginning to delegate routine tasks to AI and use it for malware and exploit development. 

The findings highlight an important shift in cybersecurity: AI does not necessarily need to invent entirely new hacking techniques to increase the threat. Automating time-consuming tasks can allow existing operators to target more systems in less time.

Why DeepSeek Is Reportedly Popular With Hackers

According to TeamT5, DeepSeek has become popular among some Chinese threat actors because of its performance, customisability and relatively low operating costs. Researchers also pointed to differences in cybersecurity safeguards between models. 

TeamT5 chief analyst Charles Li said Western AI models are also sought after, but their safety restrictions can make malicious use more difficult. DeepSeek, meanwhile, was described by the researcher as comparatively powerful while having fewer cyber-related guardrails. (Tech Times)

Importantly, researchers said they could not always determine exactly which AI model had been used in every incident. Therefore, the findings should not be interpreted as meaning every China-linked AI-assisted cyberattack involved DeepSeek. 

Cyberattack Volume Reportedly More Than Doubled

One of the biggest findings from TeamT5's research concerns scale.

According to the researchers, state-affiliated Chinese cyber groups have more than doubled the volume of attacks since they started using AI for routine work and more advanced malicious-software development. 

AI can potentially accelerate tasks such as reconnaissance, analysing targets, writing or modifying scripts and assisting with exploit development.

This means experienced hackers can spend less time on repetitive work and concentrate on higher-value parts of an operation.

AI Being Used at Different Stages of Cyber Operations

The report describes several China-linked hacking groups allegedly using AI in different ways.

TeamT5 researchers said a group tracked as Grimfengxi used DeepSeek for exploit-code development. Another group, Huapi, allegedly used a Chinese AI model believed to be DeepSeek while targeting the email infrastructure of a Taiwanese company.

A third group, Teleboyi, reportedly used AI for reconnaissance, including gathering roughly 1,000 IP addresses and mapping a target organisation's domains. (Tech Times)

These examples indicate that AI can be useful to attackers well before an actual intrusion takes place.

Western AI Models Have Also Faced Abuse

The problem isn't limited to Chinese-developed AI systems.

Western AI providers have also documented attempts to misuse their models for cyber or influence operations.

For example, OpenAI previously reported banning accounts associated with activity overlapping publicly reported threat groups and displaying characteristics consistent with cyber operations serving PRC intelligence requirements. The accounts had used AI to support phishing and scripting workflows. 

OpenAI's report on malicious AI use

This illustrates why the broader issue is better understood as AI-assisted cybercrime and state-linked cyber activity, rather than a problem involving a single chatbot.

Claude Has Faced Similar Threat-Actor Interest

Anthropic has also taken steps to restrict access from entities controlled by companies in unsupported regions, including China.

The company said in 2025 that organisations controlled from authoritarian regions could potentially use advanced AI capabilities in ways that benefit military and intelligence objectives. 

Anthropic has subsequently said it shut down CCP-sponsored cyberattacks that attempted to abuse Claude.

ChatGPT Has Also Been Targeted for Misuse

OpenAI regularly publishes reports describing malicious attempts to use its models.

In June 2026, for example, OpenAI disclosed and disrupted clusters of accounts likely originating from China that used ChatGPT in apparent covert influence operations concerning US technology and AI policies.

These cases are not identical to malware development or network intrusion, but they demonstrate the range of ways threat actors may attempt to incorporate generative AI into their operations.

Why AI Could Make Cyberattacks More Scalable

The biggest concern is not necessarily that AI suddenly turns an inexperienced person into an elite hacker.

Its immediate advantage is speed and scale.

Tasks that previously required substantial manual effort can potentially be automated or accelerated. An attacker could use AI to process large amounts of technical information, organise reconnaissance data, analyse code or assist with repetitive scripting.

This could allow the same number of attackers to operate against a much larger number of potential targets.

TeamT5's reported increase in attack volume provides evidence of how significant this productivity effect could become. 

What Should Companies and Users Do?

For organisations, AI-assisted hacking makes basic cybersecurity practices even more important. Systems should be patched promptly, internet-facing services should be protected with strong authentication, unnecessary external access should be removed and suspicious activity should be continuously monitored.

Employees should also remain cautious about phishing emails, unexpected attachments, login pages and requests for credentials, because AI can make fraudulent messages more convincing and easier to produce at scale.

For individual users, enabling multi-factor authentication, installing security updates promptly and avoiding reused passwords can significantly reduce exposure to common account-compromise techniques.

The larger lesson from the TeamT5 findings is that AI is changing the economics and speed of cyber operations. Attackers may not need revolutionary new techniques if AI allows them to automate existing ones and launch substantially more campaigns with the same resources.