Chinese state-sponsored hacker groups have radically ramped up their activity, doubling the number of cyberattacks. A key factor behind this surge has been the mass adoption of the open-source AI model DeepSeek in the daily operations of malicious actors. This is not merely a trend but a systemic shift in tactics that is reshaping the cyber threat landscape.

Analysis shows that DeepSeek has become the preferred tool for automating routine tasks related to preparing and executing attacks. Unlike more expensive and heavily guarded Western counterparts, this model offers hackers an optimal combination of power and accessibility. Its technical limitations are minimal, allowing it to be used at every stage—from intelligence gathering to writing malicious code.

Why DeepSeek Was Chosen

Interestingly, more powerful models, such as Moonshot's Kimi K3, have not been observed in attacks. The reason is simple: they are too expensive for cybercriminals. The economics of hacking dictate their own rules—attackers choose not the most advanced but the most cost-effective solutions. DeepSeek fits perfectly into this paradigm, providing sufficient functionality without excessive costs.

Practical examples confirm the scale of the problem. The Grimfengxi group used DeepSeek to generate exploits, while Teleboyi used it to scan and map targets across 1,000 IP addresses. Certain groups, such as Huapi, applied the model for direct attacks on corporate email systems. In some cases, hackers even combined DeepSeek with Western tools, as demonstrated by the Slime22 group, which used Claude Code for lateral movement across networks after breaching them.

A New Era of Cybercrime

Of particular concern is the emergence of commercial offerings. A small Chinese startup of ten people sells network-hacking software for 300,000–500,000 yuan ($44,500–74,000). This toolkit has already been used by at least four hacker groups, and one attack even employed ChatGPT. This points to the formation of an entire industry dedicated to creating AI weapons for cyberattacks.

It is telling that the trend is not limited to China. The North Korean group Kimsuky is also experimenting with local AI models. We are witnessing a global arms race in AI, where the accessibility of technology becomes a key factor. In my view, this trend will only intensify, and companies urgently need to rethink their defense strategies, considering that adversaries are now armed with cheap and effective artificial intelligence.