What happened
Chosunbiz reports that Taiwan cybersecurity research institute TeamT5’s 2025 Asia-Pacific advanced persistent threat report found Chinese-linked hacking groups using open-source AI models, including DeepSeek, at multiple stages of cyberattacks. TeamT5 said the groups were using AI to delegate repetitive tasks and develop more sophisticated malicious software, potentially expanding the scale of their operations. The report names Grimfengxi, Huapi and Teleboyi in examples involving attack-code creation, attacks on Taiwanese corporate email systems and collection of about 1,000 internet IP addresses. TeamT5 said it could not identify the model used in every incident and assessed DeepSeek’s prevalence partly from its performance, customization features, lower operating expense and comparatively weak safeguards. The claims have not been independently confirmed in the supplied source.
Chosunbiz reports that TeamT5 released its 2025 Asia-Pacific advanced persistent threat trends report on Aug. 24 and concluded that Chinese hacking groups were expanding overseas cyber operations with help from open-source AI models, including DeepSeek. According to the report as summarized by Chosunbiz, groups linked to the Chinese government had more than doubled the number of attacks while delegating simple, repetitive tasks to AI and beginning to use AI to create more sophisticated malicious software. The supplied article does not define the comparison period behind that “more than doubled” assessment or provide a total number of attacks.
TeamT5’s attribution is qualified. Chosunbiz reports that the institute cannot identify the AI model used in every hacking incident. It nevertheless assessed that DeepSeek was widely used among Chinese hackers because of what it described as the model’s high performance and customization features. The article also reports that skilled hackers were using relatively lower-performing models to expand the scale of their work and search for new infiltration paths. These statements are assessments from TeamT5, not independent findings established by the supplied source.
The report describes AI use across several operational stages. Chosunbiz says open-source models were used for target reconnaissance and for creating tools to exploit vulnerabilities. It attributes examples to three groups: Grimfengxi allegedly created attack code with DeepSeek; Huapi used a Chinese model believed to be DeepSeek against the email systems of Taiwanese corporations; and Teleboyi used DeepSeek to collect about 1,000 IP addresses from the internet and identify the domains of specific corporations.
Chosunbiz also reports that analysts considered DeepSeek attractive because its cybersecurity barriers were relatively lax and its operating expense was low. TeamT5 senior analyst Charles Li told Bloomberg, as quoted in the article, that DeepSeek was relatively high-performing but had weak mechanisms for blocking malicious use, while Western models had stricter safeguards and required more effort to circumvent.
The source says no hacking cases using Moonshot AI’s Kimi K3 had been confirmed and that TeamT5 presumed the model’s higher operating expense was a factor. It does not establish that cost was the reason for the absence of confirmed cases.
Read the primary source: biz.chosun.com ↗
Why it matters
The report describes AI as an operational tool inside cyberattacks rather than as incidental technology. If accurate, using models for reconnaissance, repetitive work and exploit-tool development could allow skilled operators to handle more targets or pursue more infiltration paths with the same personnel. It also highlights a security tradeoff around open-source and low-cost models: accessibility and customization can make them useful for legitimate users while also making misuse harder to control. The evidence remains limited to TeamT5’s assessment as reported by Chosunbiz. The source does not provide a complete attack count, victim list, damage assessment, technical samples, or independent verification that DeepSeek generated the cited code or activity.
The central significance is the reported use of AI inside an existing cyber operation. The source does not describe an autonomous attack system acting without human involvement. Instead, it describes hackers assigning selected tasks to models, including repetitive work, reconnaissance and the production of attack code. That distinction matters: the practical effect may be increased speed, volume or flexibility for skilled operators rather than a wholly new form of attack.
The reported examples also show why model safeguards can have consequences beyond a chatbot’s user interface. According to Chosunbiz’s account of TeamT5’s analysis, DeepSeek’s combination of capability, customization and low operating expense made it useful to attackers, while its relatively weak abuse-prevention mechanisms reduced friction. If the assessment is correct, a model’s safety posture can influence operational choices by malicious users, particularly when models can be adapted or run at comparatively low cost.
The report is consequential but incomplete. It does not say how many incidents involved DeepSeek, how much of the claimed increase in attacks was caused by AI, whether the named groups used official hosted access or locally operated versions, or whether the model’s outputs were accurate, novel or directly responsible for successful intrusions. It also does not document victims’ losses, affected sectors beyond the reference to Taiwanese corporate email systems, or responses from DeepSeek’s developer. Those gaps limit what can responsibly be concluded.
The claims should therefore be read as reported threat intelligence, not as a comprehensive measurement of AI-enabled cybercrime. TeamT5’s inability to identify the model in every incident is especially important because code or text alone may not reliably reveal which model produced it. The supplied source contains no independent validation from the named groups, affected companies, law-enforcement agencies or model providers.
What to watch next
The next important developments are independent technical corroboration, additional details from TeamT5 or affected organizations, and evidence tying particular model outputs to particular intrusions. Watch whether investigators identify confirmed use of other Chinese models, including Kimi K3, and whether cost or safeguards materially affect attackers’ model choices. Model providers’ responses will also matter, especially changes to abuse safeguards, monitoring and access controls for open or customizable systems. Public assessments should distinguish confirmed model use from inference based on the capabilities, cost or apparent origin of generated material.
Independent corroboration should be the first priority. Useful confirmation would include technical indicators, incident timelines, samples of generated or modified code, or statements from affected organizations that connect specific activity to DeepSeek. Further reporting should also clarify how TeamT5 distinguished DeepSeek use from use of other Chinese or open-source models and how it defined the reported increase in attacks.
The distinction between alleged and confirmed model use will remain important. Chosunbiz reports that Huapi used a Chinese model believed to be DeepSeek, while it presents DeepSeek use by Grimfengxi and Teleboyi more directly. Those different levels of certainty should not be collapsed into a single count. The lack of confirmed Kimi K3 cases is also only an observation in the source, not evidence that the model is never used or that cost alone explains its absence from identified incidents.
Security teams and policymakers will likely watch whether model access, customization and operating cost change the distribution of malicious AI use. The source does not provide operational guidance for defenders, but its examples point to reconnaissance, email-system targeting, IP collection and exploit-tool creation as areas where investigators may look for AI-assisted activity. Future assessments should show whether these tasks produce measurable improvements over conventional tooling.
Finally, watch for responses from model developers and governments. The relevant questions are whether safeguards are strengthened, whether open or customizable models can be monitored without blocking legitimate research, and whether providers disclose abuse trends in a verifiable way. Until those details emerge, the supplied report supports concern about AI-assisted scaling of cyber operations, but not precise claims about the prevalence, effectiveness or damage of DeepSeek-enabled attacks.


