DeepSeek Becomes a New Tool for Hackers? Report Claims AI Is Helping Chinese Cyber Groups Scale Attacks

Artificial intelligence is transforming industries, but the technology is also creating new challenges for cybersecurity. A recent report claims that hacking groups linked to China are increasingly using AI tools such as DeepSeek to automate parts of their operations and accelerate cyberattacks.

According to research cited in reports, Taiwanese cybersecurity firm Team5 found evidence that AI is being used at multiple stages of cyber operations, from reconnaissance to malware and exploit development.

Why Are Hackers Turning to DeepSeek?

One reason reportedly attracting cybercriminal groups to DeepSeek is its combination of relatively low cost, strong capabilities and fewer restrictions on certain cybersecurity-related requests compared with some Western AI models.

According to Team5 chief analyst Charles Li, hackers also use Western AI services, but their stricter safeguards can make certain malicious requests more difficult to carry out.

Researchers reportedly found scripts and operational logs indicating that AI tools were being incorporated into activities associated with China-linked hacking groups.

AI Can Be Used at Different Stages of an Attack

The reported research suggests that hackers aren't using AI for just one specific task. Instead, it can potentially assist with several stages of a cyberattack.

For example, the report linked a group known as Grimfengshi to the use of DeepSeek for exploit-code development. Another group, Huapi, reportedly used DeepSeek while targeting the email infrastructure of a Taiwanese company.

A separate group, Teleboyi, was reportedly observed using AI-assisted techniques to collect large numbers of IP addresses and map an organisation's online infrastructure.

These examples highlight how AI can potentially reduce the amount of time attackers need to perform repetitive research and technical tasks.

Western AI Tools Are Also Being Used

DeepSeek isn't the only AI service reportedly appearing in cyber investigations. Security researchers have also identified cases involving American AI platforms.

Cybersecurity company CyCraft reportedly found evidence that a hacking-related software firm used ChatGPT during an attack on a Western think tank. The attackers allegedly sought assistance related to developing software for decrypting data taken from a compromised computer.

Team5 also reported that a group identified as Slime22 used Anthropic's coding technology while targeting a Taiwanese technology company. Anthropic subsequently restricted services for companies controlled by China, according to the report.

Why This Matters for Cybersecurity

The growing use of AI by attackers could make cybercrime more efficient. Tasks that previously required considerable time and technical expertise can potentially be accelerated with AI assistance.

At the same time, AI companies are strengthening safeguards designed to prevent their systems from being used for malicious activities. Cybersecurity researchers are also developing new methods to detect AI-assisted attacks.

The issue is therefore becoming a race between AI-powered offensive techniques and AI-powered security tools.

AI Is a Double-Edged Technology

The reported activity does not mean that DeepSeek or other AI systems are inherently hacking tools. The same technologies can be used for legitimate software development, security research, threat detection and defensive cybersecurity.

However, the reported use of AI by sophisticated hacking groups highlights an emerging challenge: as AI becomes more capable, both attackers and defenders can use it to increase the speed and scale of their operations.

For organisations, this makes basic cybersecurity measures—including strong authentication, regular software updates, employee awareness, network monitoring and rapid response to suspicious activity—even more important.