
Chinese state-backed hacking has more than doubled since using AI.
DeepSeek is favored for its low guardrails.
Open models still trail Western frontier models in autonomous attacks.
What happened
Taiwanese security firm TeamT5 warned that state-backed hacking groups from China have more than doubled their attacks since they started using AI for routine tasks and malware development. DeepSeek is especially popular among these hackers because it's 'relatively powerful with very low cyber guardrails,' according to chief analyst Charles Li.
Why it matters
Specific groups have been linked to AI use: Grimfengxi used DeepSeek to write exploit code, Huapi relied on a Chinese model likely to be DeepSeek, and Teleboyi used the platform to collect IP addresses. ChatGPT played a role in at least one case, and a group called Slime22 used Anthropic's Claude Code to move through a Taiwanese company's systems.
What to watch
A study by the UK AI Safety Institute found that the cyber capabilities of open models have jumped sharply, but for fully autonomous attacks, they still trail Western frontier models by several months.
Ask the AI about this article →
The report from TeamT5, a Taiwanese cybersecurity firm, illustrates a significant shift in state-sponsored cyber operations. The doubling of attacks is directly linked to the adoption of AI for routine tasks and malware development. The accessibility of models like DeepSeek appears to be a key factor, as its low guardrails make it an attractive tool for generating exploit code and other malicious content.
The use of various AI models—including ChatGPT and Claude Code—by different groups shows that this is not a single-tool phenomenon but a broader integration of AI into hacking workflows. The UK AI Safety Institute's study provides a comparative framework, suggesting that while open models are rapidly improving, they are not yet at the level of Western frontier systems for fully autonomous operations. This creates a temporary but distinct capability gap, offering potential defenders a window of time to develop countermeasures.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
Ask AI anything about this article. Q&As are published on this page for other readers too.
An unknown AI model called Ox Alpha appeared on OpenRouter on August 20 and reached #1 in weekly token consump…

Observe by Snowflake has published customer evidence that its AI SRE, built on unified telemetry storage and a…

Alabama's attorney general issued a subpoena to OpenAI on Monday over an investigation into how one of its AI…

OpenAI's Tivor Sotio announced on August 24 that the 5-hour usage limit for ChatGPT Work and Codex will return…

OpenAI released a preview version of its ChatGPT desktop application for Linux on August 11, 2026 (US time)

The Japanese government adopted guiding principles on intellectual property protection for generative AI opera…
