Retour aux Actualités
SécuritéBriefing AI Understanding

Chosunbiz rapporte que TeamT5 a lié des pirates informatiques chinois à des cyberattaques assistées par DeepSeek

Chosunbiz rapporte que TeamT5 a identifié DeepSeek parmi les modèles d'IA open source utilisés par des groupes de piratage liés à la Chine pour la reconnaissance, le développement d'exploits et la création de codes d'attaque, tout en avertissant que l'attribution de modèles n'est pas toujours possible.

6 min readRead the original reporting
Source-provided image accompanying Chosunbiz reports TeamT5 linked Chinese hackers to DeepSeek-assisted cyberattacks
Rapports attribuésSource enregistrée
Éditeur
biz.chosun.com
Lien source
biz.chosun.comhttps://biz.chosun.com/en/en-it/2026/08/25/RGQ7AZXVVJCGZJU6TRODTFH6UI/?outputType=amp
Type de source
Reportage d'un média – pas d'un document de première partie.
Également cité

Ce que nous n'avons pas pu confirmer indépendamment: Cette affirmation est attribuée au point de vente nommé. Nous ne l'avons pas vérifié par rapport à un document de première partie. (biz.chosun.com)

Histoire révisée pour la dernière fois

ContexteComprenez cela en 60 secondes

Commencez ici

Termes clés

Inférence
Phase d'exécution au cours de laquelle un modèle entraîné génère des prédictions ou des sorties.
Testez-vousQuiz sur les modèles d'IA expliqués

Ce qui a changé depuis la publication

  1. Première publication
  2. This report materially advances the same TeamT5-linked event already covered in the canonical update by adding reported case details involving Grimfengxi, Huapi, Teleboyi and Slime22, and by describing alleged use of ChatGPT and Claude Code alongside DeepSeek. The new claims remain attributed to The Straits Times, TeamT5, CyCraft and material reviewed by Bloomberg News, and are not independently confirmed by AI Understanding.
  3. This Chosunbiz report materially advances the existing TeamT5 story by adding named examples and operational details: Chosunbiz reports that Grimfengxi created attack code with DeepSeek, Huapi used a Chinese model believed to be DeepSeek against Taiwanese corporate email systems, and Teleboyi used DeepSeek to collect about 1,000 IP addresses and identify corporate domains. It also includes TeamT5’s explanation that cost, customization and comparatively weak safeguards may influence model choice. These claims remain un independently confirmed in the supplied source.

Que s'est-il passé

Chosunbiz reports that Taiwan cybersecurity research institute TeamT5’s 2025 Asia-Pacific advanced persistent threat report found Chinese-linked hacking groups using open-source AI models, including DeepSeek, at multiple stages of cyberattacks. TeamT5 said the groups were using AI to delegate repetitive tasks and develop more sophisticated malicious software, potentially expanding the scale of their operations. The report names Grimfengxi, Huapi and Teleboyi in examples involving attack-code creation, attacks on Taiwanese corporate email systems and collection of about 1,000 internet IP addresses. TeamT5 said it could not identify the model used in every incident and assessed DeepSeek’s prevalence partly from its performance, customization features, lower operating expense and comparatively weak safeguards. The claims have not been independently confirmed in the supplied source.

Chosunbiz reports that TeamT5 released its 2025 Asia-Pacific advanced persistent threat trends report on Aug. 24 and concluded that Chinese hacking groups were expanding overseas cyber operations with help from open-source AI models, including DeepSeek. According to the report as summarized by Chosunbiz, groups linked to the Chinese government had more than doubled the number of attacks while delegating simple, repetitive tasks to AI and beginning to use AI to create more sophisticated malicious software. The supplied article does not define the comparison period behind that “more than doubled” assessment or provide a total number of attacks.

TeamT5’s attribution is qualified. Chosunbiz reports that the institute cannot identify the AI model used in every hacking incident. It nevertheless assessed that DeepSeek was widely used among Chinese hackers because of what it described as the model’s high performance and customization features. The article also reports that skilled hackers were using relatively lower-performing models to expand the scale of their work and search for new infiltration paths. These statements are assessments from TeamT5, not independent findings established by the supplied source.

The report describes AI use across several operational stages. Chosunbiz says open-source models were used for target reconnaissance and for creating tools to exploit vulnerabilities. It attributes examples to three groups: Grimfengxi allegedly created attack code with DeepSeek; Huapi used a Chinese model believed to be DeepSeek against the email systems of Taiwanese corporations; and Teleboyi used DeepSeek to collect about 1,000 IP addresses from the internet and identify the domains of specific corporations.

Chosunbiz also reports that analysts considered DeepSeek attractive because its cybersecurity barriers were relatively lax and its operating expense was low. TeamT5 senior analyst Charles Li told Bloomberg, as quoted in the article, that DeepSeek was relatively high-performing but had weak mechanisms for blocking malicious use, while Western models had stricter safeguards and required more effort to circumvent.

The source says no hacking cases using Moonshot AI’s Kimi K3 had been confirmed and that TeamT5 presumed the model’s higher operating expense was a factor. It does not establish that cost was the reason for the absence of confirmed cases.

Détails de la source: biz.chosun.com ↗

Pourquoi c'est important

The report describes AI as an operational tool inside cyberattacks rather than as incidental technology. If accurate, using models for reconnaissance, repetitive work and exploit-tool development could allow skilled operators to handle more targets or pursue more infiltration paths with the same personnel. It also highlights a security tradeoff around open-source and low-cost models: accessibility and customization can make them useful for legitimate users while also making misuse harder to control. The evidence remains limited to TeamT5’s assessment as reported by Chosunbiz. The source does not provide a complete attack count, victim list, damage assessment, technical samples, or independent verification that DeepSeek generated the cited code or activity.

The central significance is the reported use of AI inside an existing cyber operation. The source does not describe an autonomous attack system acting without human involvement. Instead, it describes hackers assigning selected tasks to models, including repetitive work, reconnaissance and the production of attack code. That distinction matters: the practical effect may be increased speed, volume or flexibility for skilled operators rather than a wholly new form of attack.

The reported examples also show why model safeguards can have consequences beyond a chatbot’s user interface. According to Chosunbiz’s account of TeamT5’s analysis, DeepSeek’s combination of capability, customization and low operating expense made it useful to attackers, while its relatively weak abuse-prevention mechanisms reduced friction. If the assessment is correct, a model’s safety posture can influence operational choices by malicious users, particularly when models can be adapted or run at comparatively low cost.

The report is consequential but incomplete. It does not say how many incidents involved DeepSeek, how much of the claimed increase in attacks was caused by AI, whether the named groups used official hosted access or locally operated versions, or whether the model’s outputs were accurate, novel or directly responsible for successful intrusions. It also does not document victims’ losses, affected sectors beyond the reference to Taiwanese corporate email systems, or responses from DeepSeek’s developer. Those gaps limit what can responsibly be concluded.

The claims should therefore be read as reported threat intelligence, not as a comprehensive measurement of AI-enabled cybercrime. TeamT5’s inability to identify the model in every incident is especially important because code or text alone may not reliably reveal which model produced it. The supplied source contains no independent validation from the named groups, affected companies, law-enforcement agencies or model providers.

Interactive Mechanism

Mécanisme interactif : comment cela fonctionne réellement

Explorez de manière interactive la technologie sous-jacente à ce développement.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Vérification de concept interactive+10 Points
AI Models Explained Quiz

Which component of an AI application is the machine-learning model itself?

Que regarder ensuite

The next important developments are independent technical corroboration, additional details from TeamT5 or affected organizations, and evidence tying particular model outputs to particular intrusions. Watch whether investigators identify confirmed use of other Chinese models, including Kimi K3, and whether cost or safeguards materially affect attackers’ model choices. Model providers’ responses will also matter, especially changes to abuse safeguards, monitoring and access controls for open or customizable systems. Public assessments should distinguish confirmed model use from based on the capabilities, cost or apparent origin of generated material.

Independent corroboration should be the first priority. Useful confirmation would include technical indicators, incident timelines, samples of generated or modified code, or statements from affected organizations that connect specific activity to DeepSeek. Further reporting should also clarify how TeamT5 distinguished DeepSeek use from use of other Chinese or open-source models and how it defined the reported increase in attacks.

The distinction between alleged and confirmed model use will remain important. Chosunbiz reports that Huapi used a Chinese model believed to be DeepSeek, while it presents DeepSeek use by Grimfengxi and Teleboyi more directly. Those different levels of certainty should not be collapsed into a single count. The lack of confirmed Kimi K3 cases is also only an observation in the source, not evidence that the model is never used or that cost alone explains its absence from identified incidents.

Security teams and policymakers will likely watch whether model access, customization and operating cost change the distribution of malicious AI use. The source does not provide operational guidance for defenders, but its examples point to reconnaissance, email-system targeting, IP collection and exploit-tool creation as areas where investigators may look for AI-assisted activity. Future assessments should show whether these tasks produce measurable improvements over conventional tooling.

Finally, watch for responses from model developers and governments. The relevant questions are whether safeguards are strengthened, whether open or customizable models can be monitored without blocking legitimate research, and whether providers disclose abuse trends in a verifiable way. Until those details emerge, the supplied report supports concern about AI-assisted scaling of cyber operations, but not precise claims about the prevalence, effectiveness or damage of DeepSeek-enabled attacks.

Guides et quiz associés

Modèles d'IA expliquésÉthique de l'IATestez ce que vous savez : essayez un quiz gratuit sur l'IARecherchez un terme d'IA dans notre glossaireSuivez le tracker de la réglementation de l'IA

Mises à jour et corrections

Cette histoire canonique est mise à jour lorsque l’événement en développement change matériellement. Son URL et sa date de publication originale ne changent jamais.

  • This Chosunbiz report materially advances the existing TeamT5 story by adding named examples and operational details: Chosunbiz reports that Grimfengxi created attack code with DeepSeek, Huapi used a Chinese model believed to be DeepSeek against Taiwanese corporate email systems, and Teleboyi used DeepSeek to collect about 1,000 IP addresses and identify corporate domains. It also includes TeamT5’s explanation that cost, customization and comparatively weak safeguards may influence model choice. These claims remain un independently confirmed in the supplied source.
  • This report materially advances the same TeamT5-linked event already covered in the canonical update by adding reported case details involving Grimfengxi, Huapi, Teleboyi and Slime22, and by describing alleged use of ChatGPT and Claude Code alongside DeepSeek. The new claims remain attributed to The Straits Times, TeamT5, CyCraft and material reviewed by Bloomberg News, and are not independently confirmed by AI Understanding.
Voir le journal des corrections publiques
Vous avez trouvé cela utile ?