Chinese state-affiliated cyber groups have more than doubled their attack volume since integrating open-source artificial intelligence models such as DeepSeek into their operations, according to research by Taiwanese firm TeamT5.
The findings, released on August 24, highlight the growing role of AI in cyber espionage and offensive operations. TeamT5’s chief analyst, Charles Li, noted that DeepSeek has emerged as the preferred platform among Chinese hackers due to its high performance, customization capabilities, and notably low cyber guardrails compared to Western alternatives.
Li added that Western AI models, while desirable, impose stricter restrictions that require significantly more effort to bypass. The report identifies multiple hacker groups leveraging these tools across various attack stages, from reconnaissance to vulnerability exploitation.
Among the groups cited is Grimfengxi, which used DeepSeek to generate exploit code. Another, Huapi, employed a Chinese AI model—likely DeepSeek—to target a Taiwanese company’s email infrastructure. The hacker group Teleboyi utilized the platform to compile a database of 1,000 IP addresses, mapping corporate domains for potential intrusion points.
The Moonshot-developed Kimi K3 model, though more powerful, was described as prohibitively expensive for hacker operations, with no recorded incidents involving its use. TeamT5’s analysis underscores the accelerating integration of AI in state-sponsored cyber activities and the challenges posed by unrestricted access to advanced tools.












