What happened
The Straits Times reports that TeamT5 observed Chinese state-affiliated hacking groups using DeepSeek and other AI models across multiple stages of cyberattacks. Researchers cited scripts, logs and screenshots indicating uses including reconnaissance, exploit-code generation, domain mapping and lateral movement. The report says the model used could not always be identified and that the findings have not been independently confirmed.
The Straits Times reports that Taiwanese research firm TeamT5 found Chinese state-affiliated cybergroups had more than doubled their attacks after delegating mundane tasks to AI and using it to develop malicious software. TeamT5 said it was not always possible to identify which model was used. Researchers nevertheless described DeepSeek as popular among Chinese hackers because of its performance, customizability and low operating cost, as well as what they characterized as comparatively weak cyber-safety guardrails. These are reported findings from researchers, not independently verified conclusions in the source.
According to The Straits Times, TeamT5 said it had obtained scripts and logs showing AI tools being used throughout attacks. The report describes three examples: a group called Grimfengxi allegedly used DeepSeek to create exploit code; a group called Huapi allegedly used a Chinese AI model that researchers believed was DeepSeek against a Taiwanese company’s email system; and a group called Teleboyi allegedly used the platform to collect 1,000 internet IP addresses and map a company’s domains. The source does not provide enough technical detail to assess the success or full scope of those operations.
The Straits Times also reports that Chinese hacking groups used other models. CyCraft said a company selling hacking software used ChatGPT during an attack on a Western think tank. After hackers obtained an employee’s local Signal database from a compromised computer, screenshots reviewed by Bloomberg News allegedly showed them consulting ChatGPT to help build a module intended to decrypt it. TeamT5 separately said a group called Slime22 used Claude Code to conduct lateral movement inside a Taiwanese technology company after installing Kali, a penetration-testing platform. The source says the group bypassed safeguards by posing as an engineer conducting authorized security tests.
The report says researchers found a public shared drive containing thousands of Chinese-language screenshots, including images taken as recently as February, that depicted a roughly 10-person startup developing hacking tools for sale. The tools allegedly cost between 300,000 yuan and 500,000 yuan, and the report says at least four hacking groups were customers. The Straits Times says activity linked to one group overlapped with operations publicly attributed to Mustang Panda, which the U.S. Justice Department describes as backed by the Chinese government. DeepSeek, China’s embassy in Washington and China’s Ministry of Foreign Affairs did not respond to requests for comment, according to the report.
Read the primary source: straitstimes.com ↗
Why it matters
The report indicates that AI-assisted cyber operations do not require the most advanced models to scale. Low-cost, customizable models with comparatively weak cybersecurity guardrails may help experienced attackers automate routine work and develop malicious software, potentially increasing the volume and speed of attacks against companies and institutions.
The central significance is operational scale. The Straits Times’ account suggests that attackers may use relatively ordinary language models to automate reconnaissance, generate code and perform other repetitive tasks, leaving experienced operators to coordinate campaigns and make higher-level decisions. That matters because the security impact of AI may come less from autonomous, frontier-model behavior than from making established intrusion techniques faster, cheaper or easier to repeat. The reported doubling of attacks is attributed to TeamT5 and is not independently confirmed by the source.
DeepSeek’s reported appeal also illustrates how safety controls, price and customization can influence abusive use. Researchers told The Straits Times that Chinese hackers preferred DeepSeek in part because it was inexpensive and had weaker cyber guardrails than some Western services. The source does not establish that DeepSeek caused any specific breach, that its safeguards are universally weaker, or that it was the model used in every cited incident. It does show why model availability and abuse prevention are becoming security concerns alongside model capability.
The reported use of commercial Western tools complicates a simple national or technological divide. The Straits Times says Chinese-linked actors also used ChatGPT and Claude Code, despite provider restrictions or safeguards. In the Claude Code case, TeamT5 said attackers impersonated a legitimate security tester to bypass protections. In the ChatGPT case, the source describes assistance with a decryption-related software module but does not establish whether the module worked or whether the model supplied the decisive technical knowledge. Those limits are important when assessing the practical effect of AI assistance.
For defenders, the implication is that model use may be only one component of a broader intrusion chain. The reported examples involve compromised systems, local data, reconnaissance, exploit development, penetration-testing tools and lateral movement. Logs, prompts or screenshots may help investigators identify AI assistance, but the source does not say how reliably such evidence can be collected or authenticated. Organizations therefore cannot assume that detecting a model’s fingerprints will be sufficient; the article supports attention to conventional access controls, endpoint monitoring and investigation of unusual automation, while leaving the effectiveness of specific defenses unresolved.
What to watch next
Further evidence is needed to establish how often DeepSeek or other models are used in real-world attacks, how much human expertise remains necessary, and whether AI materially improves outcomes. Watch for technical disclosures, affected organizations’ investigations, model-provider abuse reports and evidence that providers’ safeguards are being bypassed or strengthened.
The first question is whether TeamT5, CyCraft or affected organizations publish fuller technical evidence. The Straits Times reports that researchers had scripts, logs and screenshots, but the source does not include the artifacts, indicators of compromise, attack timelines or independent forensic findings. Those details would help distinguish direct model use from human-written tooling, establish whether the cited groups achieved their objectives and clarify how much of the reported increase in attacks can be attributed to AI.
Watch for confirmation from model providers and governments. DeepSeek did not respond to The Straits Times’ request for comment, while Anthropic also did not answer questions. OpenAI said it was committed to identifying, preventing and disrupting abuse of its models. The article does not report any new restriction or technical change by DeepSeek, OpenAI or Anthropic in response to these findings. Public provider investigations could clarify account controls, abuse-detection methods and whether the models’ logs support or contradict the researchers’ account.
A second area to monitor is the role of model capability and cost. The report says researchers had not recorded an incident involving Moonshot’s Kimi K3 and believed it was too expensive for hackers to run, while describing DeepSeek as sufficiently capable and cheaper. That is a researcher assessment, not a comparative study. Further evidence would be needed to determine whether cost, access, guardrails, model quality or familiarity is the main factor shaping attackers’ choices.
Finally, the report connects this story to a previous Anthropic disclosure that Chinese state-backed hackers used Claude Code in September 2025 to target 30 entities, which Anthropic characterized as the first documented large-scale cyberattack executed without substantial human intervention. The current article does not independently verify that earlier claim or establish that the newly described DeepSeek activity is autonomous. Future reporting should separate human-directed assistance, partial automation and genuinely autonomous operations, because those categories carry different risks and require different defensive and policy responses.


