China’s hackers use DeepSeek for attacks, researchers say
Chinese state-affiliated hacking groups have more than doubled their attack volume after integrating DeepSeek and other open-source AI models into their operations. TeamT5, a Taiwanese research firm, reports that these groups use AI for mundane tasks and to develop advanced malicious software. DeepSeek is favored by hackers due to its high performance, customizability, and relatively lax cybersecurity barriers, despite more powerful domestic models like Moonshot's Kimi K3 being available. The AI models are used across multiple stages of an attack, including reconnaissance and generating exploit codes for vulnerabilities. In some cases, American AI models like ChatGPT have also been used by Chinese hacking software vendors.
Chinese state-affiliated cyber groups have significantly escalated their attack capabilities by adopting open-source AI models, particularly DeepSeek. TeamT5 reports a doubling of attacks, with AI assisting in tasks from reconnaissance to exploit code generation. DeepSeek's appeal to hackers stems from its balance of performance, customizability, and low operational cost, rather than being the most powerful model available. This points to a pragmatic approach by threat actors in Asia, prioritizing accessible and effective tools over cutting-edge but potentially more restricted or expensive alternatives like Kimi K3. The integration of AI into cyber operations by groups such as Grimfengxi and Huapi demonstrates a clear shift in tactics. While US national security officials worry about advanced models, observed activity shows even less capable AI is being effectively weaponized. The use of American AI, such as ChatGPT by a hacking software company to decrypt a Signal database, further complicates the cybersecurity landscape, highlighting the dual-use nature of AI tools and the challenges in enforcing ethical guidelines across borders. The thing to watch for Asian enterprises is the increasing sophistication and scale of attacks, even from less advanced AI. The low cost and accessibility of models like DeepSeek mean that the barrier to entry for developing advanced malicious software is dropping. Companies in the region must anticipate a higher volume of AI-assisted threats and strengthen their defenses against automated reconnaissance and exploit generation.
相关文章
6 则
GPT-5.6 model family arrives in Kiro with lower cost per completed task
The pragmatic choice of AI models for cyber attacks echoes the cost-efficiency seen in other LLM adoptions.

华为发布最新技术,提升AI能力,力求打破中国对Nvidia的依赖

中国火箭热潮将海南变成太空枢纽。发射能否推动更广泛的增长?

Anthropic 将 Claude 聊天和 Cowork 合并到单一界面

Threads 新功能让播客推广节目并触达听众

