China's New Super-Advanced Weapon: The World Braces for Catastrophe
The threat of artificial intelligence (AI)-based cyberattacks is becoming increasingly terrifying. Hacker groups reportedly affiliated with the Chinese government have more than doubled the intensity of global cyberattacks after integrating open-source AI models, particularly DeepSeek, into their hacking tactics.
According to the latest report from Taiwan-based cybersecurity research firm TeamT5, the volume of cyberattacks has surged more than twofold since hackers began delegating routine hacking tasks to AI and using it to create sophisticated malware.
Amid fears among US security officials about the potential autonomy of advanced AI models such as those made by OpenAI or Anthropic, which risk spiralling out of control, Chinese hackers are instead utilising AI with more basic but effective capabilities to expand the reach of their attacks.
Compared to other more powerful local models such as Moonshot’s Kimi K3, DeepSeek has become the primary choice due to its overly lax cyber guardrails and extremely low operational costs.
“DeepSeek has become the favourite AI of Chinese hackers because it is considered reliable yet has very weak security guardrails. Western AI models are indeed highly sought after, but their security restrictions are very strict and require extra effort to breach,” said Charles Li, Chief Analyst at TeamT5, as quoted from StraitTimes based on a Reuters report on Wednesday (26/8/2026).
Several recorded instances of hackers utilising DeepSeek include:
Grimfengxi Group: Utilised DeepSeek to design exploit code for security vulnerabilities.
Huapi Group: Used a Chinese AI model (strongly indicated to be DeepSeek) to hack the email systems of technology companies in Taiwan.
Teleboyi Group: Used AI to collect 1,000 IP addresses and map the domains of target companies.
Not only local AI, Chinese hackers have also been found to outsmart leading AI models made by US technology giants to carry out their operations.
Cybersecurity firm CyCraft found evidence that a hacking software provider had consulted ChatGPT to create a software module for breaching the database of its victim’s Signal messaging application.
The startup developing hacking tools, consisting of 10 members, was found to have sold the pirated tool for 300,000 to 500,000 yuan to at least four hacker groups, including the well-known Beijing-backed Mustang Panda group.
Meanwhile, a hacker group called Slime22 was also caught utilising Anthropic’s Claude Code. They pretended to be cyber engineers conducting penetration tests, then instructed Claude Code to breach and infiltrate the internal networks of Taiwanese technology companies.
In response to this phenomenon, both OpenAI and Anthropic have stated their commitment to continue blocking and detecting any form of misuse of their AI models for illegal hacking activities. Anthropic itself noted that the autonomous hacking incident via Claude Code is the first case in the world where a large-scale cyberattack was successfully executed without significant human intervention.