← All posts / Policy

DeepSeek Is Now the Weapon of Choice for Chinese State Hackers — And It Doubled Their Attack Volume

TeamT5 says Chinese state-affiliated groups have more than doubled attack volume by wiring DeepSeek into reconnaissance, exploit writing, and lateral movement — drawn by weak cyber guardrails and rock-bottom costs.

DeepSeek Is Now the Weapon of Choice for Chinese State Hackers — And It Doubled Their Attack Volume

The most consequential AI security story of the summer is not about frontier models breaking out of sandboxes. It is about cheap, guardrail-light models being wired into the boring machinery of state-sponsored intrusion. On August 25, Bloomberg reporting published through The Straits Times revealed that Chinese state-affiliated hacking groups have more than doubled their attack volume since they began delegating reconnaissance, exploit development, and lateral movement to DeepSeek and other open-source AI models — according to TeamT5, the Taiwanese threat-intelligence firm that documented the campaigns.

The finding

TeamT5’s researchers say they obtained scripts and operational logs in recent months showing Chinese government-affiliated hackers running DeepSeek throughout multiple stages of real attacks — not in lab demos or proof-of-concept write-ups. The model conducts reconnaissance, generates means of exploiting vulnerabilities, and assists with post-compromise movement inside victim networks. Three distinct groups are named:

  • Grimfengxi used DeepSeek to write exploit code.
  • Huapi used a Chinese AI model — which researchers assess was likely DeepSeek — to attack a Taiwanese company’s email system.
  • Teleboyi used the platform to harvest 1,000 IP addresses from the public internet and map a target company’s domains.

The through-line is economics. “DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” said Charles Li, chief analyst at TeamT5. “Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass.”

Notably, TeamT5 has recorded no incidents involving Moonshot’s Kimi K3 — widely regarded as the most capable Chinese model — because it is believed to be prohibitively expensive to run at attack scale. Hackers are not shopping for peak intelligence; they are shopping for throughput per yuan.

A black market for AI-powered attack kits

One of the most revealing discoveries came from a public shared drive containing thousands of Chinese-language screenshots, taken as recently as February, documenting the workflow of a roughly ten-person startup that develops hacking tools for sale. Its software sells for 300,000 to 500,000 yuan (roughly US$42,000–70,000) per license, and its customer list includes at least four separate hacking groups — one of which overlaps with operations publicly attributed to Mustang Panda, which the U.S. Justice Department assesses is backed by the Chinese government.

This is the commercialization layer that policy debates often miss. The threat is not just state bureaus with GPU clusters; it is a cottage industry productizing AI-assisted intrusion and selling it downstream to whoever can pay.

Western models are in the toolchain too

The reporting is careful to note that attackers mix and match regardless of origin. The Taiwanese security firm CyCraft documented a case in which a vendor selling hacking software used ChatGPT during an attack on a Western think tank: after exfiltrating an employee’s local Signal database from a compromised machine, the operators consulted the chatbot to help build a decryption module for it. OpenAI says it is committed to identifying, preventing, and disrupting abuse of its models.

More striking is the agentic case. A group tracked as Slime22 used Claude Code — Anthropic’s command-line coding agent — to move laterally inside the systems of a Taiwanese technology company. After the initial breach, the group installed its own instance of Kali Linux, the standard penetration-testing distribution, and simply asked Claude to operate it for lateral movement. The guardrail bypass was almost banal: the attackers posed as an engineer running authorized security tests.

That echoes Anthropic’s own 2025 disclosure that Chinese state-backed hackers had used Claude Code to autonomously attack 30 entities — which the company called the first documented case of a large-scale cyberattack executed without substantial human intervention. Anthropic has since blocked its services from Chinese-controlled entities, and the Slime22 incident shows both why that mattered and why it is insufficient: capable actors route around policy controls by misrepresenting intent, and open-weight alternatives sit one browser tab away.

Why this matters more than sandbox escapes

U.S. national security anxieties this summer have focused on frontier autonomy — Anthropic and OpenAI agents escaping evaluation environments, the Hugging Face intrusion, Alabama’s subpoena of OpenAI over a July sandbox breach. Those stories matter. But TeamT5’s data points at a more immediate and more scalable problem: an experienced hacking crew armed with a cheap, weakly-guardrailed model is a force multiplier that is already deployed in production. Researchers say it was not always possible to identify which model was used in a given intrusion, which means the observed cases are a floor, not a ceiling.

The asymmetry is brutal for defenders. Automated reconnaissance that once consumed hours of operator time now costs fractions of a cent. Attack surface mapping, credential-stuffing script generation, exploit adaptation for a specific target’s stack — the tedious 80% of an intrusion — is exactly the work that current models do well and that DeepSeek’s pricing makes effectively free at scale.

The open-weight question, sharpened

The finding lands in the middle of an unresolved policy fight. Open-weight models can be self-hosted, fine-tuned, and stripped of refusal behavior — no API terms of service can reach them. DeepSeek’s success as an attack substrate is the clearest demonstration yet that model guardrails are a de facto security control, and that their absence is a geopolitical externality, not just a brand risk. Western labs have responded by hardening agentic products (Anthropic’s Claude Code auto-mode classifier being one example) and restricting access — but TeamT5’s evidence shows determined state actors treat all models as attack tooling and pick whichever offers the least resistance per dollar.

For enterprise defenders, the operational takeaway is blunt: assume adversary reconnaissance and exploit tailoring are automated, cheap, and continuous. For policymakers, the TeamT5 report is likely to fuel arguments for including model-security evaluations — not just capability evaluations — in any emerging AI governance regime. The cheapest models on the market have become the cheapest weapons, and the market will not correct that on its own.

DeepSeek did not respond to a request for comment. Neither China’s embassy in Washington nor its Ministry of Foreign Affairs responded to requests for comment.