뉴스로 돌아가기
보안AI Understanding 브리핑

조선비즈, TeamT5가 중국 해커를 DeepSeek 지원 사이버 공격에 연결했다고 보고

조선비즈(Chosunbiz)는 TeamT5가 정찰, 익스플로잇 개발, 공격 코드 생성 전반에 걸쳐 중국 관련 해킹 그룹이 사용하는 오픈 소스 AI 모델 중 DeepSeek를 식별했으며, 모델 속성이 항상 가능한 것은 아니라고 경고했습니다.

6 min readRead the original reporting
Source-provided image accompanying Chosunbiz reports TeamT5 linked Chinese hackers to DeepSeek-assisted cyberattacks
기여 보고녹음된 소스
출판사
biz.chosun.com
소스 링크
biz.chosun.comhttps://biz.chosun.com/en/en-it/2026/08/25/RGQ7AZXVVJCGZJU6TRODTFH6UI/?outputType=amp
소스 유형
자사 문서가 아닌 뉴스 매체를 통한 보도입니다.
또한 인용됨

자체적으로는 확인할 수 없었던 내용: 이 소유권 주장은 해당 매장에 귀속됩니다. 당사는 자사 문서와 비교하여 이를 확인하지 않았습니다. (biz.chosun.com)

마지막으로 수정된 스토리

맥락60초 안에 이해하세요

여기서 시작하세요

주요 용어

추론
훈련된 모델이 예측 또는 출력을 생성하는 런타임 단계입니다.
자신을 테스트해 보세요AI 모델 설명 퀴즈

출간 이후 달라진 점

  1. 처음 출판됨
  2. This report materially advances the same TeamT5-linked event already covered in the canonical update by adding reported case details involving Grimfengxi, Huapi, Teleboyi and Slime22, and by describing alleged use of ChatGPT and Claude Code alongside DeepSeek. The new claims remain attributed to The Straits Times, TeamT5, CyCraft and material reviewed by Bloomberg News, and are not independently confirmed by AI Understanding.
  3. This Chosunbiz report materially advances the existing TeamT5 story by adding named examples and operational details: Chosunbiz reports that Grimfengxi created attack code with DeepSeek, Huapi used a Chinese model believed to be DeepSeek against Taiwanese corporate email systems, and Teleboyi used DeepSeek to collect about 1,000 IP addresses and identify corporate domains. It also includes TeamT5’s explanation that cost, customization and comparatively weak safeguards may influence model choice. These claims remain un independently confirmed in the supplied source.

무슨 일이 일어났나요?

Chosunbiz reports that Taiwan cybersecurity research institute TeamT5’s 2025 Asia-Pacific advanced persistent threat report found Chinese-linked hacking groups using open-source AI models, including DeepSeek, at multiple stages of cyberattacks. TeamT5 said the groups were using AI to delegate repetitive tasks and develop more sophisticated malicious software, potentially expanding the scale of their operations. The report names Grimfengxi, Huapi and Teleboyi in examples involving attack-code creation, attacks on Taiwanese corporate email systems and collection of about 1,000 internet IP addresses. TeamT5 said it could not identify the model used in every incident and assessed DeepSeek’s prevalence partly from its performance, customization features, lower operating expense and comparatively weak safeguards. The claims have not been independently confirmed in the supplied source.

Chosunbiz reports that TeamT5 released its 2025 Asia-Pacific advanced persistent threat trends report on Aug. 24 and concluded that Chinese hacking groups were expanding overseas cyber operations with help from open-source AI models, including DeepSeek. According to the report as summarized by Chosunbiz, groups linked to the Chinese government had more than doubled the number of attacks while delegating simple, repetitive tasks to AI and beginning to use AI to create more sophisticated malicious software. The supplied article does not define the comparison period behind that “more than doubled” assessment or provide a total number of attacks.

TeamT5’s attribution is qualified. Chosunbiz reports that the institute cannot identify the AI model used in every hacking incident. It nevertheless assessed that DeepSeek was widely used among Chinese hackers because of what it described as the model’s high performance and customization features. The article also reports that skilled hackers were using relatively lower-performing models to expand the scale of their work and search for new infiltration paths. These statements are assessments from TeamT5, not independent findings established by the supplied source.

The report describes AI use across several operational stages. Chosunbiz says open-source models were used for target reconnaissance and for creating tools to exploit vulnerabilities. It attributes examples to three groups: Grimfengxi allegedly created attack code with DeepSeek; Huapi used a Chinese model believed to be DeepSeek against the email systems of Taiwanese corporations; and Teleboyi used DeepSeek to collect about 1,000 IP addresses from the internet and identify the domains of specific corporations.

Chosunbiz also reports that analysts considered DeepSeek attractive because its cybersecurity barriers were relatively lax and its operating expense was low. TeamT5 senior analyst Charles Li told Bloomberg, as quoted in the article, that DeepSeek was relatively high-performing but had weak mechanisms for blocking malicious use, while Western models had stricter safeguards and required more effort to circumvent.

The source says no hacking cases using Moonshot AI’s Kimi K3 had been confirmed and that TeamT5 presumed the model’s higher operating expense was a factor. It does not establish that cost was the reason for the absence of confirmed cases.

소스 세부정보: biz.chosun.com ↗

왜 중요한가요?

The report describes AI as an operational tool inside cyberattacks rather than as incidental technology. If accurate, using models for reconnaissance, repetitive work and exploit-tool development could allow skilled operators to handle more targets or pursue more infiltration paths with the same personnel. It also highlights a security tradeoff around open-source and low-cost models: accessibility and customization can make them useful for legitimate users while also making misuse harder to control. The evidence remains limited to TeamT5’s assessment as reported by Chosunbiz. The source does not provide a complete attack count, victim list, damage assessment, technical samples, or independent verification that DeepSeek generated the cited code or activity.

The central significance is the reported use of AI inside an existing cyber operation. The source does not describe an autonomous attack system acting without human involvement. Instead, it describes hackers assigning selected tasks to models, including repetitive work, reconnaissance and the production of attack code. That distinction matters: the practical effect may be increased speed, volume or flexibility for skilled operators rather than a wholly new form of attack.

The reported examples also show why model safeguards can have consequences beyond a chatbot’s user interface. According to Chosunbiz’s account of TeamT5’s analysis, DeepSeek’s combination of capability, customization and low operating expense made it useful to attackers, while its relatively weak abuse-prevention mechanisms reduced friction. If the assessment is correct, a model’s safety posture can influence operational choices by malicious users, particularly when models can be adapted or run at comparatively low cost.

The report is consequential but incomplete. It does not say how many incidents involved DeepSeek, how much of the claimed increase in attacks was caused by AI, whether the named groups used official hosted access or locally operated versions, or whether the model’s outputs were accurate, novel or directly responsible for successful intrusions. It also does not document victims’ losses, affected sectors beyond the reference to Taiwanese corporate email systems, or responses from DeepSeek’s developer. Those gaps limit what can responsibly be concluded.

The claims should therefore be read as reported threat intelligence, not as a comprehensive measurement of AI-enabled cybercrime. TeamT5’s inability to identify the model in every incident is especially important because code or text alone may not reliably reveal which model produced it. The supplied source contains no independent validation from the named groups, affected companies, law-enforcement agencies or model providers.

Interactive Mechanism

대화형 메커니즘: 실제로 작동하는 방식

이 개발의 이면에 있는 기본 기술을 대화식으로 살펴보세요.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
대화형 개념 확인+10 Points
AI Models Explained Quiz

Which component of an AI application is the machine-learning model itself?

다음에 무엇을 볼 것인가

The next important developments are independent technical corroboration, additional details from TeamT5 or affected organizations, and evidence tying particular model outputs to particular intrusions. Watch whether investigators identify confirmed use of other Chinese models, including Kimi K3, and whether cost or safeguards materially affect attackers’ model choices. Model providers’ responses will also matter, especially changes to abuse safeguards, monitoring and access controls for open or customizable systems. Public assessments should distinguish confirmed model use from based on the capabilities, cost or apparent origin of generated material.

Independent corroboration should be the first priority. Useful confirmation would include technical indicators, incident timelines, samples of generated or modified code, or statements from affected organizations that connect specific activity to DeepSeek. Further reporting should also clarify how TeamT5 distinguished DeepSeek use from use of other Chinese or open-source models and how it defined the reported increase in attacks.

The distinction between alleged and confirmed model use will remain important. Chosunbiz reports that Huapi used a Chinese model believed to be DeepSeek, while it presents DeepSeek use by Grimfengxi and Teleboyi more directly. Those different levels of certainty should not be collapsed into a single count. The lack of confirmed Kimi K3 cases is also only an observation in the source, not evidence that the model is never used or that cost alone explains its absence from identified incidents.

Security teams and policymakers will likely watch whether model access, customization and operating cost change the distribution of malicious AI use. The source does not provide operational guidance for defenders, but its examples point to reconnaissance, email-system targeting, IP collection and exploit-tool creation as areas where investigators may look for AI-assisted activity. Future assessments should show whether these tasks produce measurable improvements over conventional tooling.

Finally, watch for responses from model developers and governments. The relevant questions are whether safeguards are strengthened, whether open or customizable models can be monitored without blocking legitimate research, and whether providers disclose abuse trends in a verifiable way. Until those details emerge, the supplied report supports concern about AI-assisted scaling of cyber operations, but not precise claims about the prevalence, effectiveness or damage of DeepSeek-enabled attacks.

관련 가이드 및 퀴즈

AI 모델 설명AI 윤리알고 있는 내용을 테스트해 보세요. 무료 AI 퀴즈를 시도해 보세요.용어집에서 AI 용어를 찾아보세요.AI 규제 추적기를 따르세요

업데이트 및 수정

이 정식 스토리는 진행 중인 이벤트가 실질적으로 변경될 때 업데이트됩니다. URL과 원래 출판 날짜는 절대 변경되지 않습니다.

  • This Chosunbiz report materially advances the existing TeamT5 story by adding named examples and operational details: Chosunbiz reports that Grimfengxi created attack code with DeepSeek, Huapi used a Chinese model believed to be DeepSeek against Taiwanese corporate email systems, and Teleboyi used DeepSeek to collect about 1,000 IP addresses and identify corporate domains. It also includes TeamT5’s explanation that cost, customization and comparatively weak safeguards may influence model choice. These claims remain un independently confirmed in the supplied source.
  • This report materially advances the same TeamT5-linked event already covered in the canonical update by adding reported case details involving Grimfengxi, Huapi, Teleboyi and Slime22, and by describing alleged use of ChatGPT and Claude Code alongside DeepSeek. The new claims remain attributed to The Straits Times, TeamT5, CyCraft and material reviewed by Bloomberg News, and are not independently confirmed by AI Understanding.
공개 수정 로그 보기
이것이 유용하다고 생각하시나요?