Taiwanese cybersecurity firm warns that AI tools have more than doubled Chinese state-backed cyberattacks
Chinese state-backed hacking groups have more than doubled their cyberattacks since adopting AI tools for routine tasks and malware development DeepSeek is the preferred AI tool among Chinese hackers due to its powerful capabilities combined with minimal safety guardrails Multiple threat groups (Grimfengxi, Huapi, Teleboyi) have been documented using DeepSeek for exploit code, reconnaissance, and domain mapping Western models like ChatGPT and Claude Code are also being leveraged by threat actors
Analysis
TL;DR
- Chinese state-backed hacking groups have more than doubled their cyberattacks since adopting AI tools for routine tasks and malware development
- DeepSeek is the preferred AI tool among Chinese hackers due to its powerful capabilities combined with minimal safety guardrails
- Multiple threat groups (Grimfengxi, Huapi, Teleboyi) have been documented using DeepSeek for exploit code, reconnaissance, and domain mapping
- Western models like ChatGPT and Claude Code are also being leveraged by threat actors for sophisticated attack capabilities
- Open AI models have rapidly closed the gap in cyber capabilities, though they still trail Western frontier models by several months for fully autonomous attacks
Why It Matters
This represents a significant escalation in state-sponsored cyber warfare, where accessible AI tools are lowering the barrier to sophisticated attacks and amplifying threat actor capabilities. For AI practitioners and security professionals, it underscores the critical importance of implementing robust safety guardrails in AI models, particularly open-weight models that can be easily repurposed for malicious activities.
Technical Details
- DeepSeek dominance: Chinese state-backed groups preferentially use DeepSeek models due to their powerful capabilities paired with minimal content filtering and safety restrictions compared to Western alternatives
- Threat group attribution: TeamT5 identified specific APT groups—Grimfengxi (exploit code generation), Huapi (likely DeepSeek-dependent operations), and Teleboyi (IP/domain reconnaissance)—each leveraging AI for distinct attack phases
- Western model exploitation: Evidence shows ChatGPT used to build Signal database decryption modules (via CyCraft findings) and Claude Code employed by Slime22 group for lateral movement in Taiwanese corporate networks
- Capability gap analysis: UK AI Safety Institute research indicates open models have made sharp improvements in cyber capabilities but remain months behind Western frontier models like Claude Mythos for fully autonomous attack execution
Industry Insight
- AI model developers, particularly those releasing open-weight models, must prioritize implementing robust safety guardrails and red-teaming protocols to prevent malicious repurposing, as the current gap between capability and safety is creating significant national security risks
- Organizations should update their threat intelligence frameworks to account for AI-augmented attack patterns, including faster exploit development cycles, automated reconnaissance, and more sophisticated social engineering enabled by LLMs
- The doubling of state-sponsored attacks using AI tools suggests a coming wave of AI-amplified cyber warfare; companies should invest in AI-powered defensive capabilities and assume threat actors now have access to comparable offensive AI tools
Disclaimer: The above content is generated by AI and is for reference only.