Taiwanese cybersecurity research company has found that hacker groups affiliated with the Chinese Communist government are using artificial intelligence tools like DeepSeek to expand their attacks on overseas targets.
According to a report by Bloomberg on Monday, the latest research from “Dupo Digital Security” (TeamT5) reveals that these cybersecurity organizations have begun delegating some of the tedious tasks to AI and using it to develop advanced malicious software, resulting in more than doubled number of attacks being launched currently.
Researchers indicate that despite China having more powerful development models like Moonshot’s Kimi K2, hackers still prefer DeepSeek because of its weaker security defenses and relatively low operating costs. They have not recorded any security incidents related to Kimi K2 yet, and believe the operating costs of Kimi K2 are too expensive for hackers.
“DeepSeek is the preferred AI of Chinese (Communist) hackers because it is powerful in function, but its security protection is very weak,” said Li Tingge, chief analyst of TeamT5. “Although Western models are highly praised, their security measures are more stringent, requiring hackers to put in more effort to bypass them.”
TeamT5 states that Chinese (Communist) hackers combine DeepSeek with other open-source models for reconnaissance and generating attack vulnerabilities at different stages. Scripts and logs obtained show that in recent months, hacker groups affiliated with the Chinese government have been actively using these AI models.
For example, a hacker group named Grimfengxi has been using DeepSeek to create exploit codes. Another group named Huapi utilized a Chinese AI model to attack the email system of a Taiwanese company, which researchers believe is likely a model of DeepSeek. A third group named Teleboyi collected 1000 IP addresses using DeepSeek from the internet and mapped out a company’s domain.
Researchers discovered this situation after finding a publicly shared drive containing thousands of Chinese screenshots, with some screenshots taken as early as February this year. These images depict the workflow of a small startup company with around 10 employees developing hacker tools for sales purposes, priced between 300,000 to 500,000 yuan. The company has at least four different hacker group clients.
Each of these hacker groups is conducting different attack activities. One group’s activities overlap with the publicly documented operations of “Mustang Panda,” a group supported by the Chinese government and facing charges from the US Department of Justice.
TeamT5’s research also indicates that more stringent model security defenses have not entirely prevented Western AI tools from being misused by the Chinese Communist government.
TeamT5 states that a hacker group named Slime22 successfully infiltrated a Taiwanese technology company’s system using Anthropic’s Claude Code. After breaching the company’s system, the group set up its own Kali Linux system (a penetration testing platform) and had Claude Code use that system for lateral movement. They added that hackers disguised themselves as network security testing engineers and successfully bypassed network security measures.
Anthropic has banned Chinese-controlled companies from using its services. In September 2025, the company stated that hackers supported by the Chinese government autonomously attacked 30 entities using Claude Code, including large tech companies, financial institutions, chemical enterprises, and government agencies. The company revealed that they baited the tool to attempt penetration of these entities, emphasizing that this was the first recorded large-scale cyber attack case executed without significant human intervention.
DeepSeek did not respond to Bloomberg’s request for comments.
