Chinese state-affiliated cyber groups have more than doubled their attack volume since integrating open-source artificial intelligence models such as DeepSeek into their operations, according to research by Taiwanese security firm TeamT5.
The shift has enabled hackers to automate routine reconnaissance tasks and develop sophisticated malicious software, with DeepSeek’s offerings particularly popular due to their performance and customization capabilities. While researchers could not always pinpoint the exact AI model used in individual attacks, DeepSeek and similar tools are deployed across multiple stages, from mapping corporate domains to exploiting vulnerabilities.
TeamT5 identified several hacker groups leveraging these models. Grimfengxi used DeepSeek to generate exploit code, while Huapi reportedly employed a Chinese AI model—likely DeepSeek—to target a Taiwanese company’s email infrastructure. The group Teleboyi utilized the platform to collect 1,000 IP addresses from the internet as part of its reconnaissance efforts.
Charles Li, chief analyst at TeamT5, noted that DeepSeek has become the preferred choice among Chinese hackers because of its relatively high performance and minimal cyber guardrails. Western models, though in demand, are subject to stricter controls and require greater effort to bypass, Li added. Models such as Moonshot’s Kimi K3 are considered more powerful but remain prohibitively expensive for most hackers, with no recorded incidents involving Kimi K3 to date.













