返回新闻
安全AI Understanding 简报

据《海峡时报》报道,中国与国家有关的黑客正在使用 DeepSeek 进行攻击

《海峡时报》援引台湾研究人员和网络安全公司的话说,中国政府附属的黑客组织正在使用 DeepSeek 和其他人工智能模型来自动化侦察、利用开发和网络攻击的其他部分。

6 min readRead the original reporting
Source-provided image accompanying The Straits Times reports Chinese state-linked hackers are using DeepSeek in attacks
归因报告来源记录
出版商
straitstimes.com
来源链接
straitstimes.comhttps://www.straitstimes.com/asia/east-asia/chinas-hackers-use-deepseek-for-attacks-researchers-say
来源类型
新闻媒体的报道——不是第一方文件。

我们无法独立确认的内容: 此声明归因于指定的商店。我们没有根据第一方文件对其进行验证。 (straitstimes.com)

背景60 秒内了解这一点

从这里开始

关键术语

护栏
限制不安全或不需要的模型行为的规则、检查和控制。
测试一下自己AI 模型解释测验

发生了什么

The Straits Times reports that TeamT5 observed Chinese state-affiliated hacking groups using DeepSeek and other AI models across multiple stages of cyberattacks. Researchers cited scripts, logs and screenshots indicating uses including reconnaissance, exploit-code generation, domain mapping and lateral movement. The report says the model used could not always be identified and that the findings have not been independently confirmed.

The Straits Times reports that Taiwanese research firm TeamT5 found Chinese state-affiliated cybergroups had more than doubled their attacks after delegating mundane tasks to AI and using it to develop malicious software. TeamT5 said it was not always possible to identify which model was used. Researchers nevertheless described DeepSeek as popular among Chinese hackers because of its performance, customizability and low operating cost, as well as what they characterized as comparatively weak cyber-safety . These are reported findings from researchers, not independently verified conclusions in the source.

According to The Straits Times, TeamT5 said it had obtained scripts and logs showing AI tools being used throughout attacks. The report describes three examples: a group called Grimfengxi allegedly used DeepSeek to create exploit code; a group called Huapi allegedly used a Chinese AI model that researchers believed was DeepSeek against a Taiwanese company’s email system; and a group called Teleboyi allegedly used the platform to collect 1,000 internet IP addresses and map a company’s domains. The source does not provide enough technical detail to assess the success or full scope of those operations.

The Straits Times also reports that Chinese hacking groups used other models. CyCraft said a company selling hacking software used ChatGPT during an attack on a Western think tank. After hackers obtained an employee’s local Signal database from a compromised computer, screenshots reviewed by Bloomberg News allegedly showed them consulting ChatGPT to help build a module intended to decrypt it. TeamT5 separately said a group called Slime22 used Claude Code to conduct lateral movement inside a Taiwanese technology company after installing Kali, a penetration-testing platform. The source says the group bypassed safeguards by posing as an engineer conducting authorized security tests.

The report says researchers found a public shared drive containing thousands of Chinese-language screenshots, including images taken as recently as February, that depicted a roughly 10-person startup developing hacking tools for sale. The tools allegedly cost between 300,000 yuan and 500,000 yuan, and the report says at least four hacking groups were customers. The Straits Times says activity linked to one group overlapped with operations publicly attributed to Mustang Panda, which the U.S. Justice Department describes as backed by the Chinese government. DeepSeek, China’s embassy in Washington and China’s Ministry of Foreign Affairs did not respond to requests for comment, according to the report.

来源详情: straitstimes.com ↗

为什么这很重要

The report indicates that AI-assisted cyber operations do not require the most advanced models to scale. Low-cost, customizable models with comparatively weak cybersecurity may help experienced attackers automate routine work and develop malicious software, potentially increasing the volume and speed of attacks against companies and institutions.

The central significance is operational scale. The Straits Times’ account suggests that attackers may use relatively ordinary language models to automate reconnaissance, generate code and perform other repetitive tasks, leaving experienced operators to coordinate campaigns and make higher-level decisions. That matters because the security impact of AI may come less from autonomous, frontier-model behavior than from making established intrusion techniques faster, cheaper or easier to repeat. The reported doubling of attacks is attributed to TeamT5 and is not independently confirmed by the source.

DeepSeek’s reported appeal also illustrates how safety controls, price and customization can influence abusive use. Researchers told The Straits Times that Chinese hackers preferred DeepSeek in part because it was inexpensive and had weaker cyber than some Western services. The source does not establish that DeepSeek caused any specific breach, that its safeguards are universally weaker, or that it was the model used in every cited incident. It does show why model availability and abuse prevention are becoming security concerns alongside model capability.

The reported use of commercial Western tools complicates a simple national or technological divide. The Straits Times says Chinese-linked actors also used ChatGPT and Claude Code, despite provider restrictions or safeguards. In the Claude Code case, TeamT5 said attackers impersonated a legitimate security tester to bypass protections. In the ChatGPT case, the source describes assistance with a decryption-related software module but does not establish whether the module worked or whether the model supplied the decisive technical knowledge. Those limits are important when assessing the practical effect of AI assistance.

For defenders, the implication is that model use may be only one component of a broader intrusion chain. The reported examples involve compromised systems, local data, reconnaissance, exploit development, penetration-testing tools and lateral movement. Logs, prompts or screenshots may help investigators identify AI assistance, but the source does not say how reliably such evidence can be collected or authenticated. Organizations therefore cannot assume that detecting a model’s fingerprints will be sufficient; the article supports attention to conventional access controls, endpoint monitoring and investigation of unusual automation, while leaving the effectiveness of specific defenses unresolved.

Interactive Mechanism

互动机制:它实际上是如何运作的

以交互方式探索这一发展背后的基础技术。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
交互式概念检查+10 Points
AI Models Explained Quiz

Which component of an AI application is the machine-learning model itself?

接下来看什么

Further evidence is needed to establish how often DeepSeek or other models are used in real-world attacks, how much human expertise remains necessary, and whether AI materially improves outcomes. Watch for technical disclosures, affected organizations’ investigations, model-provider abuse reports and evidence that providers’ safeguards are being bypassed or strengthened.

The first question is whether TeamT5, CyCraft or affected organizations publish fuller technical evidence. The Straits Times reports that researchers had scripts, logs and screenshots, but the source does not include the artifacts, indicators of compromise, attack timelines or independent forensic findings. Those details would help distinguish direct model use from human-written tooling, establish whether the cited groups achieved their objectives and clarify how much of the reported increase in attacks can be attributed to AI.

Watch for confirmation from model providers and governments. DeepSeek did not respond to The Straits Times’ request for comment, while Anthropic also did not answer questions. OpenAI said it was committed to identifying, preventing and disrupting abuse of its models. The article does not report any new restriction or technical change by DeepSeek, OpenAI or Anthropic in response to these findings. Public provider investigations could clarify account controls, abuse-detection methods and whether the models’ logs support or contradict the researchers’ account.

A second area to monitor is the role of model capability and cost. The report says researchers had not recorded an incident involving Moonshot’s Kimi K3 and believed it was too expensive for hackers to run, while describing DeepSeek as sufficiently capable and cheaper. That is a researcher assessment, not a comparative study. Further evidence would be needed to determine whether cost, access, , model quality or familiarity is the main factor shaping attackers’ choices.

Finally, the report connects this story to a previous Anthropic disclosure that Chinese state-backed hackers used Claude Code in September 2025 to target 30 entities, which Anthropic characterized as the first documented large-scale cyberattack executed without substantial human intervention. The current article does not independently verify that earlier claim or establish that the newly described DeepSeek activity is autonomous. Future reporting should separate human-directed assistance, partial automation and genuinely autonomous operations, because those categories carry different risks and require different defensive and policy responses.

相关指南和测验

人工智能模型解释人工智能代理人工智能安全AI 伦理测试你所知道的——尝试免费的人工智能测验在我们的词汇表中查找人工智能术语关注AI监管追踪器
觉得这有用吗?