
Chinese state hackers doubled attacks using AI tools, TeamT5 says
State-backed hacking groups from China have more than doubled their attacks since adopting AI for routine tasks and malware development, Taiwanese security firm TeamT5 found, The Decoder reported.
DeepSeek has become the tool of choice for many of these groups.
“Because it's relatively powerful with very low cyber guardrails.”
— Charles Li, chief analyst, TeamT5
TeamT5 tied specific groups to specific tools. The group Grimfengxi used DeepSeek to write exploit code, while Huapi relied on a Chinese model likely to be DeepSeek as well. Teleboyi used the platform for reconnaissance work, collecting IP addresses and mapping domains ahead of an attack.
The pattern extends beyond DeepSeek. ChatGPT played a role in at least one case security firm CyCraft investigated, where hackers used it to build a decryption module for a Signal database. A group called Slime22 went further, using Anthropic's Claude Code to move through the systems of a Taiwanese company, according to TeamT5, a sign that state-backed groups reach for whichever model does the job, regardless of where it was built.
Guardrails on a model like DeepSeek are the safety filters meant to block requests for exploit code, malware logic, or reconnaissance scripts. A model that enforces those filters loosely doesn't need to be jailbroken to help write an attack. The hacker can often ask outright. That gap between a frontier lab's safety tuning and an open model's default behavior is what TeamT5 says is driving the jump in attack volume.
The dynamic runs in both directions. We covered how the same speed advantage is reshaping the defensive side of that equation, where security researchers use frontier models to find and patch vulnerabilities faster than manual review ever allowed. TeamT5's findings show the mirror image: the same speed that helps a defender ship a patch faster helps an attacker write working exploit code faster, and nothing currently forces that speed to favor one side over the other.
A separate study from the UK AI Safety Institute found the same trend from another angle: the cyber capabilities of open models have jumped sharply over a short period. For fully autonomous attacks, though, open models still trail Western frontier systems like Claude Mythos by several months, which means the current wave of AI-assisted hacking still relies on a human directing the model rather than the model running an intrusion on its own.
- Attack volume: more than doubled since groups adopted AI for routine tasks and malware development
- Groups using DeepSeek or a similar Chinese model: Grimfengxi, Huapi, Teleboyi
- ChatGPT's role: building a decryption module for a Signal database, per CyCraft
- Claude Code's role: helped Slime22 move through a Taiwanese company's systems, per TeamT5
- Gap to fully autonomous attacks: open models trail frontier models like Claude Mythos by several months
The mix of models tells its own story. Guardrails vary enough between labs that state-backed groups can shop for whichever one gives them the least resistance for a given task, and that shopping list now runs from DeepSeek to ChatGPT to Claude Code depending on what the job requires.
Nothing here should be taken as financial advice — just information to consider.

Comments (0)
No comments yet — be the first!
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
252AI





