Chinese Hackers Use DeepSeek to Boost Attacks, Researchers Say - Bloomberg.com
Chinese hackers are reportedly using DeepSeek AI to enhance their cyberattack capabilities, according to researchers. This integration of agentic AI into post-compromise operations allows for scaled server attacks. Cisco Talos Blog identifies this activity as UAT-10147, noting the deployment of SPECTRE with EDR bypass and a Linux rootkit. The attacks have targeted approximately 170,000 servers, automating various stages of the malicious activity. This development points to a growing trend of state-sponsored or affiliated groups leveraging advanced AI tools in cyber warfare.
The use of DeepSeek AI by Chinese hackers to automate attacks on 170,000 servers marks a significant escalation in cyber capabilities. This is not merely about more efficient attacks; it reflects a strategic shift towards AI-powered offensive operations, making detection and defense more complex for Asian enterprises. The deployment of tools like SPECTRE with EDR bypass and Linux rootkits shows a sophisticated approach, suggesting these groups are moving beyond basic scripting to intelligent, adaptive attack frameworks. For companies in markets like Singapore, South Korea, and Japan, which are frequent targets of advanced persistent threats, this development means a re-evaluation of current cybersecurity postures is critical. The ability of AI to scale attacks and bypass traditional defenses requires a corresponding upgrade in AI-driven defensive measures. The risk is that many regional businesses may not be equipped to counter such advanced, automated threats, leaving critical infrastructure and data vulnerable to exploitation by these groups.



