Chinese Hackers Amplify Attacks Using DeepSeek AI

Chinese Hackers Amplify Attacks Using DeepSeek AI

First seen 25 Aug 2026, 05:50 UTC GbhackersBusinesstimes.SgUk.Finance.YahooStraitstimesuk.investing.com 75.5

Article Content

Browse articles
ThreatCluster

Chinese state-affiliated cyber groups have significantly increased their attack volume, more than doubling it since integrating DeepSeek and other open-source AI models. Researchers from TeamT5 report that these hackers are utilizing AI to automate routine tasks and develop sophisticated malware. DeepSeek is favored for its high performance and low cybersecurity barriers, making it an attractive option despite the availability of more powerful models like Kimi K3, which remains too costly for widespread use. The AI is employed across various attack stages, including reconnaissance and exploiting vulnerabilities. Specific groups such as Grimfengxi and Huapi have been identified using DeepSeek for creating exploit codes and attacking email systems. The threat has raised concerns among US national security officials regarding the capabilities of AI in cyber warfare.

Key Points: • Chinese hackers have doubled their attack volume using DeepSeek AI. • DeepSeek is favored for its low cost and weak cybersecurity barriers. • State-affiliated groups are automating tasks and developing malware with AI.

Timeline

2026-08-22
Hermes Agent framework used
A Chinese-speaking threat actor was observed using DeepSeek with the Hermes Agent framework for cyberattacks.
Gbhackers
2026-08-25
DeepSeek AI usage reported
Chinese hackers have doubled their attack volume since integrating DeepSeek into their operations, according to TeamT5.
Businesstimes.Sg
2026-08-25
Grimfengxi exploits DeepSeek
The group Grimfengxi was reported to have used DeepSeek to create exploit codes for cyberattacks.
Uk.Finance.Yahoo
2026-08-25
Huapi attacks Taiwanese email system
The Huapi group used a Chinese AI model, likely DeepSeek, to attack a Taiwanese company's email system.
Uk.Finance.Yahoo