TeamT5 reported on August 24, 2026, that Chinese state affiliated groups more than doubled their attack volume after using DeepSeek and other AI models for routine offensive work and malware development. DeepSeek is attractive because researchers cited its performance, customisability, low cost and relatively weak c...
Research answer

Create a landscape editorial hero image for this Studio Global article: What did TeamT5 and other cybersecurity researchers report about Chinese state-affiliated hackers’ use of DeepSeek and other AI models—inclu. Article summary: TeamT5’s central finding was that Chinese state-affiliated actors are using DeepSeek and other AI models to automate routine offensive work and malware development, and that their attack volume has more than doubled sinc. Topic tags: general, news, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers
TeamT5 says Chinese state-affiliated cyber groups have more than doubled their attack volume since incorporating DeepSeek and other open-source AI models into their operations. The models are being used to automate routine tasks and help develop more advanced malicious software, making existing campaigns faster and easier to scale. 13
The findings do not show that AI independently replaces experienced hackers. Instead, they show how inexpensive models and agent frameworks can automate parts of the offensive workflow—especially reconnaissance, exploit research and repeated attack attempts—while human operators still select objectives and provide direction. 115
Researchers cited four main reasons for DeepSeek’s popularity among Chinese hackers:
That combination matters operationally. A model does not need to discover a novel vulnerability to be useful: it can help search exposed systems, modify public exploit code, interpret technical output and decide which routine step to try next.
The reporting describes China-linked groups using DeepSeek, ChatGPT and Claude Code for reconnaissance, exploit creation or adaptation, automation and the development of malicious code. It also mentions lateral movement in attacks on foreign companies and institutions. 3
The available reporting generally describes the activity as involving state-affiliated or China-linked actors collectively. It does not reliably identify a specific named advanced persistent threat group behind every reported use of AI, so those examples should not be treated as evidence that all Chinese cyber groups use the same model or workflow. 13
Commercial tools such as ChatGPT and Claude Code could assist with portions of a malicious workflow, but provider-side safety controls may refuse explicit requests to conduct offensive operations. In the Unit 42 case, the operator tested Western tools and found that their safeguards blocked the autonomous attack task; DeepSeek was then selected as the main reasoning model. 1415
This contrast is less about one model being universally more capable than another and more about how the model is deployed. DeepSeek was connected to an open-source framework without the same client-side restrictions, allowing it to operate inside a toolchain controlled by the attacker. 15
Palo Alto Networks’ Unit 42 separately documented activity by a Chinese-speaking actor using the aliases “knaithe” and “KnYuan.” The operator configured DeepSeek as the reasoning engine behind Hermes Agent, an open-source, terminal-capable agent framework. The setup could enumerate vulnerabilities, retrieve public exploit code and attempt exploitation with limited human supervision. 155
The agent targeted more than 460 internet-facing systems. Reporting on the wider campaign says at least three organizations were breached through exploitation of a Citrix NetScaler vulnerability. The figure of 460 refers to targets or attack attempts—not 460 successful compromises—and the operation combined autonomous and conventional activity. 4
That distinction is important. The case does not show DeepSeek breaking into hundreds of systems on its own. It shows an operator using an AI model to automate the repetitive middle of an attack: finding exposed targets, matching them to known vulnerabilities, obtaining public exploit material and trying the next candidate.
The clearest risk is scale. When a low-cost model is connected to an agent framework with terminal access, tasks that once required sustained manual effort can be repeated across many internet-facing systems. AI can therefore lower the operational barrier to high-volume reconnaissance and exploitation. 1615
But the same case also highlights the limits of the technology. Successful compromise still depended on exposed services, known vulnerabilities and usable public exploit code. AI increased the speed and volume of attempts; it was not, by itself, the cause of every breach. 515
For defenders, the practical priority remains reducing that attack surface: patch internet-facing products, remove unnecessary exposure and monitor unusual automated reconnaissance and exploitation patterns. The broader lesson from TeamT5 and Unit 42 is that AI-assisted attacks are becoming more economical and repeatable—even when the underlying techniques are familiar.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
TeamT5 reported on August 24, 2026, that Chinese state affiliated groups more than doubled their attack volume after using DeepSeek and other AI models for routine offensive work and malware development.
TeamT5 reported on August 24, 2026, that Chinese state affiliated groups more than doubled their attack volume after using DeepSeek and other AI models for routine offensive work and malware development. DeepSeek is attractive because researchers cited its performance, customisability, low cost and relatively weak cyber safety guardrails compared with Western services.
In a separate Unit 42 case, a Chinese speaking actor connected DeepSeek to the open source Hermes Agent framework and used it to target more than 460 internet facing systems, with at least three organizations breached...