Cyberspace is becoming a new arena where AI plays the role of not only a defender but also an attacker. My analysis of the latest data shows a worrying trend: Chinese state-sponsored hacker groups have significantly intensified their activities, doubling the number of attacks. A key factor behind this surge has been the mass adoption of the open-source AI model DeepSeek in their arsenal, which allows them to automate routine tasks and increase the efficiency of their hacks.

Why DeepSeek Became the Number One Choice

Contrary to the common belief that the most sophisticated AI systems pose the greatest threat, reality has proven otherwise. Attackers are betting on accessibility and minimal restrictions. Powerful Western models, such as Kimi K3 from Moonshot, while outperforming competitors in performance, remain too expensive and heavily regulated for mass use in criminal activities. This is precisely why DeepSeek, with its almost complete lack of technical barriers and low cost, has become the ideal tool for scaling up attacks.

My analysis shows that this model is used at all stages of cybercriminal activity. For example, the Grimfengxi group uses DeepSeek to generate exploits—code used for hacking. Another group, Teleboyi, uses it to collect hundreds of IP addresses and map out targets for future attacks. In one incident involving an attack on the email system of a Taiwanese company, researchers found traces of this very AI model.

AI in Action: From Phishing to Bypassing Defenses

AI-based tools are becoming increasingly sophisticated. The Slime22 group, for instance, used a combination of Kali Linux and Claude Code to move within the network of a compromised technology company. Notably, the hackers successfully convinced the AI that they were engineers conducting testing with management's permission, allowing them to bypass security mechanisms.

Notably, this trend is not limited to China. The North Korean group Kimsuky is also exploring the use of local AI models. Moreover, offers to sell AI-generated hacking software have already appeared on the market, priced from 300,000 to 500,000 yuan (approximately $44,500–74,000). At least four hacker groups have already used this tool, and one attack even involved ChatGPT.

Expert Opinion: We are on the brink of a new era of cyberwarfare, where AI becomes an equal participant. The current situation requires not just strengthening defenses but also rethinking the very paradigm of security. Companies, especially in the financial and cryptocurrency sectors, need to implement AI solutions for real-time automatic threat detection and neutralization; otherwise, their vulnerability to new hacking tools will only grow.