← All news·2026-08-25·3 min read

Artificial intelligence doubles the number of attacks from Chinese state-backed hackers

UK AI Safety Institute says cyber security capabilities of open source models “have grown sharply”, but are still behind Western cutting edge models for complete autonomy. AI has democratized state sponsored cyber attacks like it has democratized software development. Tasks previously requiring teams of experts can now be automated by a single model. These are actual cases with real actors and victims.

aisecuritychinacybersecurity

Chinese state sponsored hacking groups have doubled their activity using AI. DeepSeek (without any safeguards) is their preferred tool. They use Claude Code (Anthropic’s dev assistant) to automate navigation and circumvent corporate networks.

Specific Groups and Methods

The Taiwan-based cyber intelligence company TeamT5 has revealed that Chinese state-sponsored hacking groups have doubled their activity by using AI. The main AI tool they are using is called DeepSeek, which TeamT5 describes as “a relatively powerful Chinese language model with very low thresholds for making harmful queries.”

Open-Source Models as Weapons

TeamT5 and another cyber intelligence company, CyCraft, have also discovered how some hacking groups are using AI to carry out cyber attacks. Grimfengxi uses DeepSeek to craft exploits. Huapi employs Chinese language models for scanning and gathering information. Teleboyi uses AI to collect IPs and analyze domain names. Slime22 utilizes Claude Code (Anthropic’s developer assistant) to automate navigation and circumvent corporate networks. ChatGPT was also employed to develop a Signal DB decryptor.

Source: the-decoder.com

Free course

Stop reading about AI — start building with it

The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.

Start free →
EAEvgenii Arsentev

Author

Evgenii Arsentev

PhD · Chief Executive Officer, digital health