
Chinese state-affiliated cyber groups have more than doubled their attack volume since incorporating DeepSeek and other open-weight artificial intelligence models into their operations, according to TeamT5, a Taiwanese research firm. The hackers are now using AI to handle routine tasks and to develop sophisticated malicious software, and DeepSeek has emerged as the model of choice because of its strong performance, low cost, and weak built-in safety restrictions.
Why DeepSeek appeals to state-linked hackers
TeamT5 chief analyst Charles Li said DeepSeek’s combination of capability and minimal guardrails is what draws Chinese threat actors. “DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” Li said. “Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass.”
Researchers also pointed to operating cost as a deciding factor. More capable Chinese models exist, but they remain too expensive for routine offensive use. TeamT5 noted that Moonshot’s Kimi K3 is more powerful than DeepSeek, yet Kimi K3 is prohibitively expensive for hackers to operate at scale, and the firm has not recorded any incidents involving Kimi K3 to date.
How the models are being used across the attack chain
DeepSeek and similar open-weight models are now deployed across multiple stages of an intrusion, from reconnaissance through exploiting vulnerabilities. In recent months, TeamT5 obtained scripts and logs that show Chinese government-affiliated hackers leaning on these models throughout their operations rather than only at a single step.
Three named groups illustrate the pattern:
- Grimfengxi used DeepSeek to create exploit codes.
- Huapi used a Chinese AI model, likely DeepSeek, to attack a Taiwanese company’s email system.
- Teleboyi used the platform to collect 1,000 IP addresses from the internet and map company domains.
Researchers cautioned that it is not always possible to identify which specific AI model powered a given attack, so attribution to DeepSeek is often a best estimate based on the tooling observed.
What the broader research community has found about DeepSeek
Independent benchmarks published in peer-reviewed journals show that DeepSeek-R1 is competitive with leading Western models on knowledge-intensive tasks in Chinese. A comparative study published in the Journal of Medical Systems evaluated DeepSeek-R1 and ChatGPT-4o on 600 multiple-choice questions from the 2024 Chinese National Medical Licensing Examination. DeepSeek-R1 posted an overall accuracy of 92.0%, compared with 87.2% for ChatGPT-4o, a statistically significant difference. The advantage was strongest in the low-difficulty question group, where DeepSeek-R1 reached 95.9% against ChatGPT-4o’s 92.0%.
A separate observational study published in JMIR Formative Research tested GPT-4-turbo and DeepSeek-R1 on the 2024 Taiwan Audiologist Qualification Examination, a 300-question test spanning six subject areas. ChatGPT achieved 80.3% overall accuracy and DeepSeek reached 79.3%, both well above the 60% passing threshold. Item-level comparison found no statistically significant difference between the two models, with substantial agreement on answers. Both systems performed well on reverse logic questions but struggled with graph-based items, where ChatGPT scored 18% and DeepSeek scored 36%. The authors concluded that both models demonstrate strong professional knowledge and stable reasoning, while cautioning that errors mean they should be used under educator supervision in clinical training contexts.
What defenders should watch next
TeamT5’s findings suggest two near-term shifts for security teams. First, attack scripts and logs now routinely contain AI-generated artifacts, so threat hunting should include prompts for unusual code style, automated translation patterns, and model-style comments embedded in malware. Second, because DeepSeek is favored for its low cost and permissive defaults, defenders should expect experimentation with other open-weight Chinese models if pricing or availability changes.
For organizations in Taiwan and other frequently targeted regions, the practical takeaway is that AI-assisted intrusion activity is no longer theoretical. Reconnaissance, exploit development, and email-system compromise have all been observed in the wild, and the volume of attempts attributed to Chinese state-linked groups continues to climb.
FAQ
Which AI model are Chinese hackers using the most?
DeepSeek. TeamT5 says DeepSeek is the preferred model for Chinese state-affiliated hackers because it is relatively powerful, inexpensive to run, and has weak cyber guardrails compared with Western alternatives.
Are more capable Chinese AI models available?
Yes. Moonshot’s Kimi K3 is described as more powerful than DeepSeek, but it remains too expensive for hackers to operate at scale, and TeamT5 has not recorded any incidents involving Kimi K3.
What kinds of tasks are hackers handing off to AI?
TeamT5 observed DeepSeek being used for reconnaissance, exploit code development, attacks on email systems, and large-scale collection of IP addresses and domain mapping, covering multiple stages of the intrusion chain rather than a single step.
This article summarizes reporting from yahoo.com. See our editorial disclaimer for how our articles are produced.
Run a free scan to see your AI Visibility Score, SEO rating, and local citation accuracy.