TeamT5 ties doubled Chinese state hacker attacks to DeepSeek
TL;DR
- TeamT5 says Chinese state-affiliated groups have more than doubled attack volume since wiring DeepSeek and other open-source AI into their operations.
- Grimfengxi generated exploit code, Huapi hit a Taiwanese company's email system, and Teleboyi collected 1,000 IP addresses and mapped domains.
- Chief analyst Charles Li says DeepSeek wins on weak guardrails and cost; more capable Kimi K3 stays too expensive to be used at hacker scale.
Chinese state-affiliated hacking groups have more than doubled their attack volume since delegating reconnaissance and malware development to open-source AI, according to Taiwanese threat-intelligence firm TeamT5, in research reported by Bloomberg.
The preferred tool is DeepSeek. "DeepSeek is the AI of choice for Chinese hackers because it's relatively powerful with very low cyber guardrails," Charles Li, TeamT5's chief analyst, told Bloomberg, adding that Western models are "highly sought-after but their guardrails are much more strict and require a lot more effort to bypass."
TeamT5 named three groups. Grimfengxi used DeepSeek to generate exploit code. Huapi used a Chinese AI model, likely DeepSeek, against a Taiwanese company's email system. Teleboyi used the platform to collect 1,000 IP addresses and map corporate domains.
Cost is the other half of the story. Moonshot's Kimi K3 is more capable but too expensive for these operators to run at hacker scale, and TeamT5 says it has documented no incidents involving it. The firm also flagged other reuse of commercial AI in Chinese operations, including a group it calls Slime22 using Anthropic's Claude to move laterally through a Taiwanese tech company's systems, and hackers turning to OpenAI's ChatGPT to help decrypt Signal databases.
The finding rests on a single source, TeamT5 says it wasn't always possible to identify which specific AI model was used in a given intrusion, and neither the affected Taiwanese company nor the DeepSeek versions are named. It lands alongside other Taiwan-China stories on our radar this week, including Taiwan's indictment of nine people over Nvidia B300 server smuggling.
Originally reported by bloomberg.com
Read the original article →Original headline: TeamT5: Chinese State Groups Grimfengxi, Huapi and Teleboyi Turn to DeepSeek to Automate Exploits and Recon