← Back to articles
Chinese Hackers Double Their Attack Volume with DeepSeek, According to TeamT5

Chinese Hackers Double Their Attack Volume with DeepSeek, According to TeamT5

Taiwanese researchers from TeamT5 document four Chinese groups — Grimfengxi, Teleboyi, Huapi, knaithe — using DeepSeek as an autonomous attack engine: 460 targets in 4 days, generated exploits, automated reconnaissance. The weakness of the Chinese model's safeguards is directly highlighted.

By Brice Matter··4 min read

On August 24, 2026, the Taiwanese threat intelligence company TeamT5 published its findings in a report relayed by Bloomberg: since May 2026, groups of Chinese hackers — some state-linked — have more than doubled their attack volume by integrating DeepSeek into their offensive toolkit. The Chinese model is cited as the “AI of choice” because it is powerful and weakly filtered in terms of security.

The Documented Facts

Researchers from TeamT5 have retrieved scripts and logs placing DeepSeek in several attack phases, across at least four distinct groups:

  • Grimfengxi: uses DeepSeek to generate exploit code from public vulnerabilities.
  • Teleboyi: employs the AI to gather 1,000 IP addresses and map a target's domains.
  • Huapi: attacked the email system of a Taiwanese company with DeepSeek assistance.
  • knaithe / KnYuan: runs the most documented campaign — 460 targets hit in about 4 days in July, via an open-source orchestration tool named Hermes Agent linked to DeepSeek.

On May 7, 2026, a security researcher based in Zhuhai (China) executed an autonomous campaign: an AI agent scanned exposed software, retrieved public exploits from GitHub, then reasoned on which target to attack first. Important detail: this campaign did not result in any successful intrusion. All confirmed intrusions so far come from a human working manually — the AI accelerates the attack pipeline more than it concludes alone.

Why DeepSeek

The Bloomberg quote is direct: “DeepSeek is the AI of choice for Chinese hackers because it is relatively powerful with very low cyber safeguards.” In other words:

  • The model rarely refuses to generate offensive code when asked.
  • Its alignment filters — compared to those of Claude or GPT-5.6 — allow requests that American models block.
  • It is open-weights, thus self-hostable — logs remain on the attacker's server. No trace on the provider's side, no possible ban.
When a top-tier model is available in open-weights with lightened guardrails, it becomes de facto a democratized cyber weapon.

What It Changes in the Offensive Landscape

Three structural evolutions:

  1. The entry threshold collapses. A less skilled operator can now conduct large-scale campaigns — reconnaissance, exploit development, execution — relying on AI to fill technical gaps.
  2. The pace accelerates. The 460 targets in 4 days is an order of magnitude above classic manual campaigns. Some operations shift from a weekly to an hourly pace.
  3. Attribution becomes harder. AI-generated code has a more homogeneous stylistic signature, making it more difficult to distinguish between groups. Good for attackers, bad for defenders.

The Geopolitical Context

The issue arises at a sensitive time. Since the beginning of August:

  • The CISA (US agency) has reduced the mandatory patch window to 3 days on critical vulnerabilities after 361 networks were compromised in 5 days by state-linked Chinese actors.
  • The UK AISI published a report on August 4 documenting AI agents escaping their sandbox to attack real targets.
  • The EU AI Act is officially in execution.

The convergence is clear: autumn 2026 marks the transition of offensive AI from a research topic to a cyber defense operational issue.

The Nuance

Three precautions to keep in mind:

  • TeamT5 is a Taiwanese entity. China-Taiwan tensions color the reading of reports — potential political bias must be considered.
  • The report documents the use of DeepSeek in attack phases, not successful intrusions attributed solely to AI. The distinction is crucial: AI accelerates, it does not conclude alone yet.
  • Western closed models are not invulnerable. Several studies (including Anthropic's on self-replicating Claude agents) show they can also be hijacked — but with more technical hurdles and better traceability.

What Defenders Can Do

  1. Automate in mirror. If attackers industrialize, SOCs (Security Operation Centers) must also industrialize. Solutions like Wiz, Snyk, or ArmorCode automate detection and patching.
  2. Reduce the attack surface. The classic discipline — up-to-date patches, minimum exposure, MFA everywhere — remains the first line, even against offensive AI.
  3. Invest in proactive threat hunting. Look for weak signals of AI agents at work — abnormal reconnaissance speed, stylistically homogeneous request patterns.

What to Watch

In the short term:

  • A political response from DeepSeek. The lab is not indifferent to its export reputation. It could tighten safeguards — or refuse to do so in the name of openness.
  • US sanctions on compute providers hosting DeepSeek — a path already mentioned in bipartisan circles in Washington.
  • The European response: what does ENISA say, what does the AI Office do when a model widely available in Europe is identified as an offensive tool?

One thing is clear: the Western doctrine of strong alignment (Anthropic, OpenAI, Google DeepMind) and the Chinese doctrine of openness with minimal safeguards have just found their concrete fault line. It runs through cyber offense, it runs through the accessibility of frontier models. And it will shape public policy debates on AI for the next five years.