The Taiwanese security firm TeamT5 has determined that state-sponsored Chinese hacker groups have more than doubled their number of attacks since the routine deployment of AI chatbots. At least four groups primarily rely on the Chinese language model DeepSeek, while another additionally tested Anthropic’s coding tool Claude Code. The results became public on August 24, 2026.
TeamT5 identifies four active hacker groups
As reported by Bloomberg citing TeamT5, the increase in activity is directly linked to the offloading of routine tasks to AI. The group Grimfengxi reportedly has DeepSeek write exploit code, while Huapi used a Chinese language model – presumably also DeepSeek – against the email system of a Taiwanese company.
Teleboyi tasked an AI model with collecting around 1,000 IP addresses and mapping corporate domains, reconnaissance work that would have taken human analysts significantly longer. The group Slime22 went furthest: it ran Claude Code and posed as an authorized security tester to bypass internal protections at the compromised Taiwanese technology company. The number of attacks has reportedly more than doubled as a result – independently unverified, as TeamT5 has not yet made its raw data public.
The affected companies and authorities are located mostly in Taiwan, which has already been at the center of AI-driven attacks from China: in August, autonomous AI agents compromised 85 government accounts within four days and reached into Taiwan’s nuclear oversight body and several energy providers. Unlike that case, which used open agent frameworks such as Hermes and OpenClaw, the groups documented by TeamT5 rely on commercial chat interfaces and coding tools built for legitimate developer work.
DeepSeek is seen as a tool with few restrictions
DeepSeek has established itself as the preferred tool because it is powerful and barely restricted by security filters – so TeamT5 chief analyst Charles Li told Bloomberg. The low price adds to the appeal: the groups can run the model at scale without incurring high compute costs.
Moonshot’s model Kimi K3 does not appear in the documented cases, because the groups reportedly consider it too expensive to operate. The finding fits into a series of similar cases: in August, a lone hacker going by “knaithe” used the open-source framework Hermes Agent to automate attacks on more than 460 internet-facing systems, though largely without success. TeamT5 stresses that the current finding concerns state-sponsored groups and thus goes beyond lone attackers.
Other state-affiliated actors are also systematically expanding their AI use: the North Korean group Kimsuky has been running its own offline AI environment for phishing and malware since March 2026, so as not to send data to external providers.
What matters now is whether providers like DeepSeek and Anthropic can tighten controls on accounts from high-risk regions without restricting regular access for developer teams. It also remains open whether TeamT5 will publish its raw data and attack logs so other security teams can independently verify the methods.


