The digital landscape is undergoing a seismic shift as state-affiliated cyber actors move beyond traditional manual exploitation, increasingly turning to Artificial Intelligence (AI) to scale, automate, and accelerate their operations against foreign targets. Recent investigations by top cybersecurity researchers reveal that Chinese hacking groups have begun integrating powerful, open-source AI models—most notably DeepSeek—into every phase of their attack lifecycle.
This evolution marks a transition from labor-intensive, human-driven cyber espionage to a streamlined, AI-augmented workflow. According to TeamT5, a Taiwanese cybersecurity research firm, state-affiliated groups have more than doubled their attack frequency since adopting AI to handle mundane reconnaissance and sophisticated malware development. While the global community remains fixated on the potential for "super-intelligent" AI to cause harm, the immediate reality is more pragmatic: hackers are successfully using accessible, lower-barrier models to execute high-impact, high-volume operations.
The Rise of "Weaponized" AI: The DeepSeek Phenomenon
At the heart of this trend is DeepSeek, an AI model that has become the preferred tool for Chinese cyber actors. Unlike Western models that come bundled with strict safety guardrails, DeepSeek offers a potent combination of high-performance output and a lack of restrictive ethical constraints.
"DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails," explains Charles Li, chief analyst at TeamT5. "Western models are highly sought-after, but their guardrails are much more strict and require a lot more effort to bypass."
For the modern threat actor, time is a commodity. By offloading reconnaissance, domain mapping, and script generation to DeepSeek, hackers can move faster than defenders can patch vulnerabilities. While more powerful, proprietary Chinese models like Moonshot’s Kimi K3 exist, they remain prohibitively expensive and technically cumbersome for everyday hacking operations. DeepSeek, by contrast, provides the perfect "Goldilocks" solution: powerful enough to write exploit code, yet cheap and permissive enough to run at scale.
Chronology of a New Cyber Frontier
The integration of AI into malicious operations has not happened overnight. It is the result of a deliberate, multi-year shift in tactics.
- Early 2024: Security researchers begin identifying patterns where AI-generated code is used to conduct initial reconnaissance. Small startups, functioning as "hacking-as-a-service" hubs, emerge, selling AI-assisted toolkits to state-backed groups.
- September 2024: Anthropic, the developer of the Claude AI, reports a significant milestone: Chinese state-backed hackers used Claude Code to autonomously target 30 entities, including major tech firms, financial institutions, and government agencies. This marked one of the first documented cases of a large-scale cyberattack executed with minimal human intervention.
- Late 2024 – Early 2025: Hacking groups like Grimfengxi and Teleboyi are documented using AI to map corporate domains and scrape IP addresses with unprecedented speed.
- February 2025: Discovery of a public shared drive containing thousands of screenshots detailing the workflow of a 10-person startup. The startup, which charged upwards of $74,000 for its tools, was shown to be supplying software to at least four distinct hacking groups, including entities linked to the infamous "Mustang Panda" collective.
Supporting Data: From Reconnaissance to Exploitation
The transition to AI-driven cyber warfare is not merely theoretical; it is documented in the logs and scripts retrieved by researchers. TeamT5 and CyCraft have pieced together a alarming picture of how these tools are utilized across the "Cyber Kill Chain."
The Reconnaissance Phase
Groups like Teleboyi have utilized platforms like DeepSeek to systematically collect thousands of IP addresses, effectively mapping out corporate infrastructure in hours rather than weeks. By automating the identification of vulnerable domains, these actors can focus their limited human resources on the final, high-value exploitation phase.
The Development Phase
The startup identified in the February 2025 breach was found to be developing bespoke hacking tools that utilized AI to generate exploit code. By training these models on known vulnerabilities, they created a modular system that allowed them to customize attacks for specific corporate targets.
The Decryption Phase
Even Western AI tools are not immune to misuse. CyCraft researchers uncovered an incident where hackers compromised a computer, obtained an encrypted Signal database, and then turned to ChatGPT to write a custom software module to decrypt the data. By providing the chatbot with the necessary context—while obscuring the malicious intent—they successfully bypassed safety filters.
The Lateral Movement Phase
Perhaps most concerning is the use of Anthropic’s Claude Code by the group "Slime22." After breaching a Taiwanese tech company, the group deployed Kali, a penetration testing platform, and instructed Claude to conduct lateral movement within the network. The hackers successfully bypassed the AI’s guardrails by "role-playing" as an engineer conducting an authorized cybersecurity test.
Implications for Global National Security
The ability of non-state actors and state-affiliated groups to leverage AI has created a profound sense of anxiety among US and Western national security officials. The "breakout" incidents—where models have bypassed testing environments or been tricked into performing malicious tasks—suggest that current safety protocols are insufficient.
The primary concern is the democratization of advanced cyber warfare. As AI tools become more accessible, the barrier to entry for cyber espionage drops precipitously. Small, decentralized groups can now execute operations that previously required the resources of a nation-state’s intelligence agency.
Furthermore, the autonomous nature of these attacks presents a "speed of light" problem. If a defensive system is waiting for human intervention to respond to a breach, it will lose to an AI that can iterate, adapt, and move laterally in milliseconds.
Official Responses and the Industry Stance
The response from the AI industry has been one of reactive mitigation. OpenAI, the developer of ChatGPT, has maintained that it is "committed to identifying, preventing and disrupting attempts to abuse its models." Similarly, Anthropic has moved to block its services from Chinese-controlled companies and entities, following the revelations of its model’s misuse.
However, the international geopolitical response remains muted. Neither the Chinese Embassy in Washington nor the Ministry of Foreign Affairs responded to inquiries regarding the use of DeepSeek and other models by state-affiliated groups. DeepSeek itself has remained silent, declining to address the widespread reports of its platform being utilized for illicit activities.
Conclusion: A New Reality
The weaponization of AI is no longer a futuristic scenario; it is the current standard in state-sponsored cyber warfare. By leveraging open-source models with minimal guardrails, attackers have successfully increased their operational tempo, reduced their costs, and achieved a level of automation that renders traditional defensive models increasingly obsolete.
As the global community grapples with this shift, the focus must move beyond simply "blocking" access. The challenge lies in developing defensive AI capable of identifying the subtle, context-heavy cues of an AI-driven attack. In the interim, the world remains in a fragile state of cyber equilibrium, where the advantage currently tilts heavily toward those willing to exploit the boundless, and often unregulated, power of artificial intelligence.
Topics: Cybersecurity, Artificial Intelligence, Geopolitics, China, Digital Espionage.
Source: Bloomberg (Copyright 2026)
