Loading market data...

Chinese Hackers Double Attacks With DeepSeek as TeamT5 Flags Guardrail Gap

Chinese Hackers Double Attacks With DeepSeek as TeamT5 Flags Guardrail Gap

Chinese state-affiliated hackers are now running twice as many attacks as they did before adopting AI, and DeepSeek is the tool they reach for first, according to security firm TeamT5. The finding flips the assumption that offensive AI risk comes mainly from advanced frontier models.

Why DeepSeek Won the Hacker Vote

TeamT5's report points to a simple calculation: DeepSeek is powerful enough for the job and carries very low cyber guardrails. Western models put up stricter walls that take more effort to bypass. For operators scaling up output, the cheaper, more permissive tool wins.

The firm logged no incidents involving Moonshot's Kimi K3, a more powerful model whose running costs are prohibitive for hacking groups. That gap matters. The threat isn't coming from the most capable systems — it's coming from the ones that are good enough and don't fight back.

Three Teams, One Model

TeamT5 obtained scripts and logs that place DeepSeek across multiple attack stages. A group tracked as Grimfengxi used it to generate exploit code. Another, Teleboyi, used it to collect 1,000 IP addresses and map target domains. A third, Huapi, hit a Taiwanese company's email system with a model believed to be DeepSeek.

Those are different jobs in different phases of an attack, and one tool handled all of them.

The Claude Code Workaround

Chinese groups aren't sticking to Chinese models. A group called Slime22 breached a Taiwanese tech firm, installed Kali, and directed Claude Code to run lateral movement. They got past the safety layers by claiming to be engineers doing authorized tests.

That fits a broader pattern. Anthropic concluded in June that AI now handles advanced attack work for hackers who lack the skill to do it themselves.

Ten People, One Product, Four Customers

CyCraft traced a 10-person Chinese startup selling intrusion software for 300,000 to 500,000 yuan, or roughly $44,500 to $74,000. At least four hacking groups bought it. The same company also used ChatGPT during an attack.

The selling of AI-assisted intrusion tools is becoming a small-business line.

Beyond China

Chinese groups aren't alone in this shift. North Korea's Kimsuky is also testing local models, per the same research. OpenAI has said it's committed to identifying, preventing, and disrupting attempts to abuse its models.

The next question is whether the guardrail gap that made DeepSeek attractive closes anytime soon — and what happens to attack volumes when it doesn't.