Chinese hackers double cyberattacks using AI like DeepSeek
Translated from Korean, summarized and contextualized by DistantNews.
At a glance
- Chinese government-linked hacking groups are doubling their cyberattack frequency by using AI tools like DeepSeek.
- These groups leverage AI for tasks ranging from information gathering to writing malicious code, increasing efficiency with the same personnel.
- While some AI models offer higher performance, hackers favor DeepSeek due to its strong capabilities, lower cost, and less stringent cybersecurity restrictions compared to Western models.
Chinese government-affiliated hacking organizations have significantly increased their cyberattack frequency, reportedly doubling their efforts by employing artificial intelligence tools, including DeepSeek. This strategic use of AI allows these groups to automate and expedite various stages of cyber operations.
Analysis from Taiwanese cybersecurity firm TeamT5 indicates that these hacking groups are delegating repetitive tasks to AI, from initial intelligence gathering to the development of exploit code. This delegation enables them to conduct more numerous attacks with their existing human resources. The study noted that while not all AI models used in these attacks were identified, DeepSeek is a preferred choice for Chinese hackers.
Charles Lee, a senior analyst at TeamT5, explained that DeepSeek is favored for its combination of strong performance and relatively low cybersecurity guardrails, making it easier for Chinese hackers to utilize. While Western AI models are also popular, their stricter guardrails require more effort to circumvent.
Researchers found that hackers utilized open-source AI models like DeepSeek for multiple phases of their operations. The hacking group 'Grimfengxi,' for instance, used DeepSeek to create exploit code targeting vulnerabilities. Another group, 'Huapi,' is suspected of using a Chinese AI model, likely DeepSeek, to attack the email systems of Taiwanese companies. The group 'Teleboyi' employed DeepSeek for information collection, gathering 1,000 IP addresses and identifying target company domains.
The report also revealed a broader Chinese hacking ecosystem, with evidence of small firms developing and selling hacking tools. These tools, priced between 300,000 and 500,000 yuan, were sold to at least four different hacking organizations. Some of these activities overlapped with those of 'Mustang Panda,' a hacking group identified by the U.S. Department of Justice as being supported by the Chinese government.
DeepSeek is relatively powerful, and the cybersecurity guardrails are very low, making it the preferred AI for Chinese hackers.
Originally published by Dong-A Ilbo in Korean. Translated, summarized, and contextualized by our editorial team with added local perspective. Read our editorial standards.