TeamT5 reported that some Chinese state linked hacking groups more than doubled their attack volume after assigning routine work to DeepSeek and other open source AI models. DeepSeek reportedly stood out for its performance, low operating cost, customizability and relatively weak cyber safety guardrails.
Research answer

Create a landscape editorial hero image for this Studio Global article: What did Taiwanese threat-intelligence firm TeamT5’s August 25, 2026 report reveal about Chinese state-linked hackers’ use of AI—including t. Article summary: TeamT5’s evidence suggests that AI is primarily a force multiplier for Chinese state-linked intrusion operations: delegating repetitive work to DeepSeek and other open-source models reportedly more than doubled some grou. Topic tags: general, general web, user generated, news. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts w
Taiwanese threat-intelligence firm TeamT5 says Chinese state-linked hacking groups have more than doubled the volume of their attacks after incorporating DeepSeek and other open-source AI models into routine operational work. The report’s central finding is not that AI is independently conducting every intrusion, but that it can remove enough repetitive work to let existing operators pursue more targets at lower cost. 457
TeamT5 traced AI use across several stages of intrusion activity, including reconnaissance, vulnerability scanning, exploit development, malware-related work and operations after a network has been compromised. The firm based its assessment on scripts and logs obtained from recent campaigns, while warning that those artifacts do not always identify the exact model used in each incident. 47
That distinction matters. The reported increase of more than two times is TeamT5’s assessment of attack volume among the groups it studied—not a definitive count of every cyberattack linked to China. AI appears to be helping operators delegate mundane work, shorten parts of the attack cycle and scale activity, rather than replacing human direction altogether. 57
According to TeamT5’s reported analysis, DeepSeek offered a practical combination of capabilities for cyber operations:
The trade-off helps explain why the most capable model is not necessarily the most useful to an attacker. TeamT5 reportedly viewed more powerful systems such as Moonshot’s Kimi K3 as less attractive for these operations because of higher costs and stronger safeguards. The available reporting does not establish that Kimi K3 was used in the incidents TeamT5 reviewed. 7
TeamT5 identified several groups using AI for different jobs in the intrusion chain:
Grimfengxi reportedly used DeepSeek to create vulnerability-exploitation code. That example places the model beyond simple information gathering: it was being used to help produce code intended to take advantage of a weakness in a target system. 7
Teleboyi reportedly used DeepSeek to collect about 1,000 IP addresses from the internet and map a target organization’s domains. This is reconnaissance—the process of building a picture of a potential victim before attempting an intrusion. The activity demonstrates how AI can accelerate target discovery, but mapping infrastructure alone does not prove that a successful breach followed. 7
Huapi reportedly used a Chinese AI model against a Taiwanese company’s email system. TeamT5 believed the model was probably DeepSeek, but could not conclusively identify it. That uncertainty is an important reminder that model attribution cannot always be inferred from an attack’s code or behavior. 7
The activity was not confined to Chinese open-source models. TeamT5-linked reporting said Slime22 used Anthropic’s Claude Code after breaching a Taiwanese technology company and installing Kali Linux, a penetration-testing platform, to assist with lateral movement inside the network. The operators allegedly framed the activity as authorized engineering testing to get around safeguards. 7
This case also illustrates why defensive teams cannot focus on one model or one country of origin. Attackers may combine locally hosted or open-source systems with commercial Western tools, depending on the task and the controls they encounter.
The report described a broader market around AI-assisted intrusion operations. A Chinese startup with roughly 10 employees was reportedly selling intrusion software for 300,000 to 500,000 yuan—about $44,500 to $74,000—to at least four hacking groups. ChatGPT was also reportedly used during one attack. 7
North Korea-linked group Kimsuky was reportedly testing locally hosted AI models as well. Local deployment can give operators greater control over the model and its data, while potentially reducing dependence on external services and their abuse-detection systems. The available reporting supports the testing claim, but does not establish how effective those local models were in live operations. 7
Anthropic has separately reported that AI can lower the technical barrier to sophisticated cybercrime, allowing actors with limited technical skills to carry out operations that previously required substantially more expertise. That finding is consistent with TeamT5’s broader picture: the immediate risk may come less from a single superhuman system than from ordinary operators gaining faster access to coding, reconnaissance and workflow automation.
OpenAI said it works to identify, prevent and disrupt attempts to misuse its models. 7
TeamT5’s findings point to a measurable operational effect: AI-assisted workflows can increase the number of attacks that a group attempts by taking over repetitive tasks. But the evidence should not be read as proof that DeepSeek autonomously carried out every reported intrusion.
Three limitations are especially important:
The clearest conclusion is therefore narrower—and more actionable—than the idea of fully autonomous hacking: inexpensive, customizable AI is making it easier for established threat actors to industrialize parts of the attack process. Defenders should assume that reconnaissance, code generation and post-compromise workflows may be accelerated by multiple kinds of models, not just DeepSeek.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
TeamT5 reported that some Chinese state linked hacking groups more than doubled their attack volume after assigning routine work to DeepSeek and other open source AI models.
TeamT5 reported that some Chinese state linked hacking groups more than doubled their attack volume after assigning routine work to DeepSeek and other open source AI models. DeepSeek reportedly stood out for its performance, low operating cost, customizability and relatively weak cyber safety guardrails.
The documented activity ranged from reconnaissance and exploit code generation to email attacks and lateral movement, while Western tools such as Claude Code and ChatGPT also appeared in the broader ecosystem.