Cybersecurity analysts have recorded a worrying trend: state-sponsored hacker groups from China have doubled the intensity of their attacks. A key factor behind this surge is the mass adoption of the open-source AI model DeepSeek in the operational processes of attackers. This is not just a random tool, but a strategic choice that is fundamentally changing the landscape of digital threats.
Why DeepSeek Became the Weapon of Choice
Contrary to the widespread belief that the most sophisticated AI systems pose the greatest danger, the reality has turned out to be different. Attackers are betting on relatively inexpensive and accessible models. DeepSeek, thanks to its power and minimal technical restrictions, is ideally suited for automating routine cyberattack tasks. Western counterparts, such as Kimi K3 from Moonshot, while superior in performance, remain too expensive for mass use in criminal activities. It is the price and freedom of action that make DeepSeek an ideal tool for scaling up malicious operations.
How Hackers Apply AI in Practice
I managed to examine fragments of scripts and attack logs where DeepSeek appears at various stages. For example, the Grimfengxi group used the model to generate exploits—ready-made code for hacking. Another group, Teleboyi, used AI to collect over 1,000 IP addresses and compile a detailed map of targets. In one incident, the Huapi group attacked the email system of a Taiwanese company, using the Chinese AI model to bypass protective mechanisms.
Of particular interest is the case of the Slime22 group, which hacked a technology company in Taiwan, installed Kali Linux, and gave Claude Code a command to move within the network. The attackers convinced the AI that they were engineers testing the system with permission, thereby bypassing its defenses. This demonstrates a new level of social engineering aimed at the algorithms themselves.
Separately, the emergence of commercial offerings is worth noting. A ten-person startup sells network hacking software priced from 300,000 to 500,000 yuan (approximately $44,500–74,000). This tool has already been used by at least four hacker groups, and one attack even employed ChatGPT. OpenAI claims it is actively blocking such abuse, but it is clear this is an arms race.
My expert take: This trend is just the tip of the iceberg. While Western companies spend billions protecting their proprietary models, open AI systems are becoming a "gray zone" for cybercriminals. The market urgently needs new security standards and international cooperation, otherwise we will see exponential growth in automated attacks that traditional defense methods simply cannot handle.