TeamT5, a Taiwanese cybersecurity firm, reports that state-backed hacking groups from China have more than doubled their attack frequency since integrating artificial intelligence into routine operations and malware creation. Chief analyst Charles Li notes that DeepSeek is particularly favoured among these attackers because the model offers significant power with minimal cyber guardrails. Specific incidents confirm this trend, with the Grimfengxi group using DeepSeek to generate exploit code while Huapi relied on a similar Chinese model. Other groups like Teleboyi employed the platform to harvest IP addresses and map domains, and Slime22 used Anthropic’s Claude Code to navigate the systems of a local company. Evidence also shows ChatGPT assisting in building decryption modules for Signal databases.
The shift matters because open-source models now provide capabilities that previously required extensive human effort or proprietary software. A study by the UK AI Safety Institute indicates that the cyber capabilities of these open models have increased sharply, allowing attackers to automate tasks faster. However, fully autonomous attacks still lag behind Western frontier models like Claude Mythos by several months. This gap suggests current AI tools act as force multipliers rather than complete replacements for human operators.
* DeepSeek is popular due to low safety restrictions
* UK AI Safety Institute tracks open model progress
* Western models remain ahead in full autonomy




