My latest observations in the cybersecurity field point to a worrying trend: state-sponsored hacker groups from China have significantly intensified their activities. Analysis of recent data shows that the number of attacks has doubled, and the key catalyst for this surge has been the mass adoption of open-source AI models, particularly DeepSeek, in their arsenal.
Why DeepSeek Became the Weapon of Choice
This shift challenges the established notion that only the most sophisticated and expensive AI systems pose a threat. In practice, operators are increasingly turning to relatively inexpensive and accessible models to simply scale up their operations. The reason is simple: DeepSeek offers sufficient computing power with almost no restrictions, while Western counterparts, although popular, are equipped with much stricter safeguards that are harder to bypass.
Notably, powerful models like Moonshot's Kimi K3 have not been spotted in the hands of malicious actors—they are simply too expensive for mass campaigns. The choice of DeepSeek is a pragmatic decision driven by the economics of cybercrime.
How Exactly Hackers Use AI
I have managed to trace how DeepSeek is integrated into various stages of attacks. For example, the Grimfengxi group uses it to generate exploits, while Teleboyi uses it to collect thousands of IP addresses and build a target map. The Huapi group attacked the email systems of Taiwanese companies through a Chinese AI model, and Slime22 went even further by breaching a technology firm and using Claude Code for lateral movement within the network, deceiving the AI system with a fake testing scenario.
Of particular note is the emergence of an entire market for AI-powered hacking tools. A ten-person startup sells software for penetrating networks for 300,000–500,000 yuan (approximately $44,500–74,000). At least four hacker groups have already used this tool, and one attack even employed ChatGPT. Interestingly, the North Korean group Kimsuky is also experimenting with local AI models, pointing to a global trend.
My verdict: we are witnessing the democratization of cyber weapons. Cheap AI models are blurring the line between the capabilities of state structures and small criminal groups. This calls for a revision of defense strategies: the threat now stems less from the complexity of algorithms than from their accessibility and mass adoption. The security industry will have to adapt to a new reality where AI becomes not just a tool, but the main battlefield.