Chinese hackers use DeepSeek to scale attacks
Analysis based on 7 articles · First reported Aug 25, 2026 · Last updated Aug 25, 2026
Chinese state-affiliated hackers have more than doubled their cyberattacks by integrating DeepSeek and other open-source AI models into their operations, according to a report by Taiwanese research firm TeamT5. The hackers use AI for reconnaissance, exploit creation, and lateral movement, targeting foreign companies and institutions. Specific groups such as Grimfengxi, Huapi, Teleboyi, and Slime22 have been identified using DeepSeek, ChatGPT, and Claude Code. The report also highlights a startup selling hacking tools for 300,000-500,000 yuan, with customers including groups linked to Mustang Panda. Anthropic and OpenAI have acknowledged and are working to disrupt such abuse.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard