Taiwanese cybersecurity firm TeamT5 has documented a surge in Chinese state-affiliated hacking activity linked to the use of open-source artificial intelligence models, particularly DeepSeek. According to the research, attack volumes have more than doubled since these tools were incorporated into operational workflows.
TeamT5 identified multiple hacking groups leveraging DeepSeek across different attack phases. The Grimfengxi collective used the platform to generate exploit code, while Huapi targeted a Taiwanese company’s email system using a Chinese AI model. Another group, Teleboyi, collected 1,000 internet IP addresses to map corporate domains, according to the findings.
Charles Li, chief analyst at TeamT5, attributed the preference for DeepSeek to its accessibility and weak cybersecurity barriers. Li stated that DeepSeek is favored by Chinese hackers because it is powerful yet imposes minimal restrictions, unlike Western models that face stringent safety protocols. Li added that while models such as Moonshot’s Kimi K3 are more capable, their operational costs remain prohibitive for widespread use in cyber operations.
The report highlights a shift in tactics, with hackers integrating AI tools into reconnaissance, vulnerability exploitation, and lateral movement within corporate networks. TeamT5’s analysis underscores the dual-use nature of open-source AI, which can both enhance productivity and lower the barriers to entry for malicious actors.
Separately, the article referenced promotional material for the Tech Titans strategy, which reported gains of 231.5% for Siemens Energy and 189% for Sandisk since its November 2023 launch. The piece also included unrelated promotional content for financial tools and discounts, which are not part of the core cybersecurity findings.













