Editorial illustration for Taiwan Firm: AI Tools Double Chinese State-Backed Cyberattacks
Taiwan Firm: AI Tools Double Chinese State-Backed...
Chinese state-backed hacking groups have more than doubled their attack volume since folding AI tools into their daily workflow, according to Taiwanese cybersecurity firm TeamT5. The firm's research, reported by Bloomberg, points to a shift already underway rather than a future risk: hackers are using AI models right now to write exploit code, map networks, and speed up tasks that once took teams of people days to finish.
DeepSeek shows up repeatedly in TeamT5's findings, tied to groups including Grimfengxi, Huapi, and Teleboyi. ChatGPT and Anthropic's Claude Code turn up too, linked to separate incidents documented by TeamT5 and Taiwanese security firm CyCraft. The pattern cuts across model makers and countries of origin, suggesting this isn't a single vendor's problem.
TeamT5's chief analyst, Charles Li, has a specific theory about why one platform draws more attention from state-backed hackers than the rest. His answer, laid out in the firm's Bloomberg interview, gets at a tension running through the entire AI industry right now: the gap between how capable a model is and how hard it is to stop someone from misusing it.
State-backed hacking groups from China have more than doubled their attacks since they started using AI for routine tasks and malware development, according to Taiwanese security firm TeamT5 (via Bloomberg).
Why this matters
TeamT5's numbers point to something we've been watching build for a while: the gap between "AI safety guardrails" and actual field use is where the real risk lives. DeepSeek's appeal to groups like Grimfengxi isn't mysterious. It's capable and it doesn't ask many questions. That's a product decision with consequences, and it's now showing up in intrusion data, not just red-team demos.
For developers and founders building on open or lightly-restricted models, this is a reminder that "low guardrails" is a feature to some users, not a bug. The market incentive to ship permissive tools is real, and state-backed actors will find them faster than compliance teams can patch the gap. For researchers, TeamT5's report is a useful data point for arguments about model release strategy: this is what happens when capability outpaces restriction, measured in attack volume, not hypotheticals.
Worth tracking next: whether other national CERTs start publishing similar before-and-after attack counts tied to specific model adoption. That's the kind of evidence that turns guardrail debates from theoretical to actuarial.
Further Reading
- TeamT5 ties doubled Chinese state hacker attacks to DeepSeek - AI Weekly
- China's hackers use DeepSeek for attacks, researchers say - The Straits Times
- TeamT5: Chinese state-backed hackers more than doubled attacks using AI - NewsBytes
- AI aids nation-state hackers but also helps US spies to ... - TechCrunch