Cybercrime is entering a new era, and the key driver of this shift is the accessibility of artificial intelligence. My analysis of recent trends shows that state-backed hacker groups from China have doubled the intensity of their attacks, and this happened not because of the development of ultra-sophisticated algorithms, but thanks to the mass adoption of relatively inexpensive open-source AI models such as DeepSeek.

Why DeepSeek Became the Weapon of Choice

Contrary to the widespread belief that only the most advanced and expensive neural networks pose the main threat, reality has proven otherwise. Cybersecurity experts have noted that attackers are increasingly abandoning complex Western platforms in favor of simpler and cheaper alternatives. The reason is simple: DeepSeek offers sufficient computing power to handle routine hacking tasks, yet it has virtually no technical restrictions and costs a fraction of its competitors.

For example, the more powerful Kimi K3 model from Moonshot, despite its capabilities, has not been spotted in any attack. It is too expensive for cybercriminals. Meanwhile, DeepSeek fits perfectly into their budget, allowing them to automate processes and scale up operations without significant investment.

How AI Is Used in Real Attacks

Analysis of intercepted scripts and attack logs shows that DeepSeek is used at every stage—from generating exploits to reconnaissance. One group used it to create hacking code, another to collect and organize thousands of IP addresses to build a target map. In some cases, hackers even deceived the AI by posing as engineers testing the system with management approval to bypass protective mechanisms.

Particular attention should be paid to the emergence of a shadow market for ready-made AI hacking tools. One such startup, consisting of just ten people, sells software for penetrating networks at prices ranging from 300,000 to 500,000 yuan (approximately $44,500–74,000). At least four hacker groups have already used this tool, and one attack even involved ChatGPT.

Western AI developers, such as OpenAI, claim to be actively combating abuse, but Chinese hackers are not alone in their pursuit of new methods. The North Korean group Kimsuky is also testing local models, pointing to a global trend.

My verdict: The cybersecurity market underestimates the threat posed by cheap AI models. While regulators and corporations focus on restricting access to top-tier Western neural networks, attackers have already found a loophole in the form of open and accessible alternatives. This is not a temporary phenomenon but a fundamental shift that will require a complete rethink of the digital asset protection paradigm.