Artificial intelligence doubles the number of attacks from Chinese state-backed hackers
UK AI Safety Institute says cyber security capabilities of open source models “have grown sharply”, but are still behind Western cutting edge models for complete autonomy. AI has democratized state sponsored cyber attacks like it has democratized software development. Tasks previously requiring teams of experts can now be automated by a single model. These are actual cases with real actors and victims.
Chinese state sponsored hacking groups have doubled their activity using AI. DeepSeek (without any safeguards) is their preferred tool. They use Claude Code (Anthropic’s dev assistant) to automate navigation and circumvent corporate networks.
Specific Groups and Methods
The Taiwan-based cyber intelligence company TeamT5 has revealed that Chinese state-sponsored hacking groups have doubled their activity by using AI. The main AI tool they are using is called DeepSeek, which TeamT5 describes as “a relatively powerful Chinese language model with very low thresholds for making harmful queries.”
Open-Source Models as Weapons
TeamT5 and another cyber intelligence company, CyCraft, have also discovered how some hacking groups are using AI to carry out cyber attacks. Grimfengxi uses DeepSeek to craft exploits. Huapi employs Chinese language models for scanning and gathering information. Teleboyi uses AI to collect IPs and analyze domain names. Slime22 utilizes Claude Code (Anthropic’s developer assistant) to automate navigation and circumvent corporate networks. ChatGPT was also employed to develop a Signal DB decryptor.
Source: the-decoder.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →▌ Related guides

Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles