Security

DeepSeek: Chinese hackers double number of attacks

2 min read

TL;DR Too Long; Didn’t read

The Taiwanese security company TeamT5 has determined that state-affiliated Chinese hacker groups have more than doubled their number of attacks thanks to AI tools. Four identified groups primarily use the language model DeepSeek for exploit code, reconnaissance, and camouflage, and one also used Anthropic's Claude Code according to TeamT5. DeepSeek is considered the preferred tool because it is powerful and barely restricted by security filters, according to TeamT5 chief analyst Charles Li.

A hacker figure sits in front of two screens with a DeepSeek logo sticker, while two red arrows grow upward from the keyboard, surrounded by several broken shield icons representing attack targets. Image generated with GPT Image 2

Key takeaways

  • TeamT5 counts at least four Chinese hacker groups using AI-assisted attack techniques.
  • The group Grimfengxi has exploit code written directly by DeepSeek.
  • Slime22 disguised itself with Claude Code as an authorized security tester to bypass protective mechanisms.
  • Teleboyi automates the collection of IP addresses and mapping of corporate networks with AI.
  • Moonshot's model Kimi K3 has not appeared in the attacks so far – TeamT5 considers it too expensive to operate.
  • Bloomberg published the TeamT5 findings on August 24, 2026.

The Taiwanese security firm TeamT5 has determined that state-sponsored Chinese hacker groups have more than doubled their number of attacks since the routine deployment of AI chatbots. At least four groups primarily rely on the Chinese language model DeepSeek, while another additionally tested Anthropic’s coding tool Claude Code. The results became public on August 24, 2026.

TeamT5 identifies four active hacker groups

As reported by Bloomberg citing TeamT5, the increase in activity is directly linked to the offloading of routine tasks to AI. The group Grimfengxi reportedly has DeepSeek write exploit code, while Huapi used a Chinese language model – presumably also DeepSeek – against the email system of a Taiwanese company.

Teleboyi tasked an AI model with collecting around 1,000 IP addresses and mapping corporate domains, reconnaissance work that would have taken human analysts significantly longer. The group Slime22 went furthest: it ran Claude Code and posed as an authorized security tester to bypass internal protections at the compromised Taiwanese technology company. The number of attacks has reportedly more than doubled as a result – independently unverified, as TeamT5 has not yet made its raw data public.

The affected companies and authorities are located mostly in Taiwan, which has already been at the center of AI-driven attacks from China: in August, autonomous AI agents compromised 85 government accounts within four days and reached into Taiwan’s nuclear oversight body and several energy providers. Unlike that case, which used open agent frameworks such as Hermes and OpenClaw, the groups documented by TeamT5 rely on commercial chat interfaces and coding tools built for legitimate developer work.

DeepSeek is seen as a tool with few restrictions

DeepSeek has established itself as the preferred tool because it is powerful and barely restricted by security filters – so TeamT5 chief analyst Charles Li told Bloomberg. The low price adds to the appeal: the groups can run the model at scale without incurring high compute costs.

Moonshot’s model Kimi K3 does not appear in the documented cases, because the groups reportedly consider it too expensive to operate. The finding fits into a series of similar cases: in August, a lone hacker going by “knaithe” used the open-source framework Hermes Agent to automate attacks on more than 460 internet-facing systems, though largely without success. TeamT5 stresses that the current finding concerns state-sponsored groups and thus goes beyond lone attackers.

Other state-affiliated actors are also systematically expanding their AI use: the North Korean group Kimsuky has been running its own offline AI environment for phishing and malware since March 2026, so as not to send data to external providers.

What matters now is whether providers like DeepSeek and Anthropic can tighten controls on accounts from high-risk regions without restricting regular access for developer teams. It also remains open whether TeamT5 will publish its raw data and attack logs so other security teams can independently verify the methods.

Frequently asked questions

Is DeepSeek as a company involved in the attacks?

No. The hacker groups use the publicly available model like any other user; TeamT5 does not hold DeepSeek as a company responsible for the misuse.

Which companies were specifically attacked?

TeamT5 does not name any companies, only industries and the location Taiwan. Slime22 targeted a Taiwanese technology company whose identity has not been disclosed.

How can companies protect themselves against AI-assisted reconnaissance?

Security researchers recommend stricter access controls for accounts posing as external testers, as well as closer scrutiny of unusually fast pull request or support activity. Specific recommendations from TeamT5 are not yet available.

Is Kimi K3 therefore safer than DeepSeek?

Not fundamentally – TeamT5 simply has not found any attacks using the model so far, because the groups consider it too expensive to operate. That may change once costs fall.

Are targets outside Taiwan also affected?

TeamT5 names only targets in Taiwan in the current analysis; whether the groups use the same methods against companies in Europe or the US has not yet been documented.

Sources (2)
  1. Bloomberg: Chinese Hackers Ramp Up Attacks Using DeepSeek AI, Researchers Say
  2. Implicator.ai: Chinese Hackers Double Attack Volume Using DeepSeek AI

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog