An analysis of the latest trends in cybersecurity reveals a troubling pattern: state-sponsored hacker groups from China have significantly intensified their activities, doubling the number of attacks. A key catalyst for this surge has been the widespread adoption of open-source artificial intelligence models, particularly DeepSeek, which have taken on a significant portion of the attackers' routine operations.
Why the choice fell on open-source AI models
Notably, the surge in activity contradicts the established belief that the most dangerous AI-powered attacks come exclusively from the most sophisticated and expensive systems. In practice, operators prefer to use relatively simple and accessible models for the mundane task of scaling up malicious activity. The reason is obvious: low cost and minimal technical restrictions. More powerful competitors, such as Kimi K3 from Moonshot, remain off the hackers' radar—they are too expensive for their purposes. DeepSeek, however, offers an optimal balance: sufficient power and an almost complete absence of "safety barriers," unlike Western counterparts, where bypassing built-in restrictions requires significantly more effort.
Practical application of AI in attacks
The scale of AI usage is impressive. In the analysis of attack logs and scripts to which access was obtained, DeepSeek appears at various stages. For example, the Grimfengxi group used it to generate exploits, while Teleboyi used it to collect 1,000 IP addresses and map out target domains. In one incident, the Huapi group attacked the email system of a Taiwanese company through a Chinese AI model.
Particular attention deserves the case of the Slime22 group, which, after breaching a technology company in Taiwan, used Claude Code to move within the network, convincing the AI that it was a legitimate engineer conducting testing. This demonstrates a new level of social engineering aimed directly at the algorithms themselves.
The shadow economy of cyber weapons
The development of infrastructure for such attacks is also telling. A Chinese startup of ten people was identified selling software for hacking networks at prices ranging from 300,000 to 500,000 yuan (approximately $44,500–74,000). This toolkit has already been used by at least four hacker groups, and ChatGPT was also employed in one of the attacks. Notably, the trend is not limited to China: the North Korean group Kimsuky is also experimenting with local AI models.
This shift in tactics is not just an evolution but a revolution in cybercrime. The cheapness and accessibility of AI tools democratize the capabilities for sophisticated attacks, making them available to groups of any level. The security industry will have to adapt to a new reality where defending against AI requires not only technical solutions but also an understanding of the psychology of algorithms, which are now becoming both the primary weapon and the primary target.