Overview
- TeamT5 and other security firms reported on Tuesday that Chinese state-linked groups have adopted DeepSeek and similar models and have more than doubled their attack volume since delegating routine tasks to AI.
- Researchers say DeepSeek is popular because it offers high performance at low cost and can be customized or self-hosted, which lowers barriers for attackers and weakens safety guardrails.
- Security teams documented AI use across the attack lifecycle, including scanning targets, writing exploit code, mapping domains and helping with lateral movement inside breached networks.
- Analysts identified specific groups—Grimfengxi, Huapi, Teleboyi and Slime22—and Palo Alto Networks’ Unit 42 found a Hermes Agent campaign using DeepSeek that targeted more than 460 systems with limited human oversight.
- Investigators also uncovered a small start-up selling AI-assisted hacking tools to multiple customers for roughly 300,000–500,000 yuan per package and found cases where Western models such as ChatGPT and Anthropic’s Claude Code were abused, complicating attribution and response.