返回新聞
安全性AI Understanding 簡報

根據《海峽時報》報道,中國與國家有關的駭客正在使用 DeepSeek 進行攻擊

《海峽時報》引述台灣研究人員和網路安全公司的話說,中國政府附屬的駭客組織正在使用 DeepSeek 和其他人工智慧模型來自動化偵察、利用開發和網路攻擊的其他部分。

6 min readRead the original reporting
Source-provided image accompanying The Straits Times reports Chinese state-linked hackers are using DeepSeek in attacks
歸因報告來源記錄
出版商
straitstimes.com
來源連結
straitstimes.comhttps://www.straitstimes.com/asia/east-asia/chinas-hackers-use-deepseek-for-attacks-researchers-say
來源類型
新聞媒體的報道-不是第一方文件。

我們無法獨立確認的內容: 此聲明歸因於指定的商店。我們沒有根據第一方文件對其進行驗證。 (straitstimes.com)

背景60 秒內了解這一點

從這裡開始

關鍵術語

護欄
限制不安全或不必要的模型行為的規則、檢查和控制。
測試一下自己AI 模型解釋測驗

發生了什麼事

The Straits Times reports that TeamT5 observed Chinese state-affiliated hacking groups using DeepSeek and other AI models across multiple stages of cyberattacks. Researchers cited scripts, logs and screenshots indicating uses including reconnaissance, exploit-code generation, domain mapping and lateral movement. The report says the model used could not always be identified and that the findings have not been independently confirmed.

The Straits Times reports that Taiwanese research firm TeamT5 found Chinese state-affiliated cybergroups had more than doubled their attacks after delegating mundane tasks to AI and using it to develop malicious software. TeamT5 said it was not always possible to identify which model was used. Researchers nevertheless described DeepSeek as popular among Chinese hackers because of its performance, customizability and low operating cost, as well as what they characterized as comparatively weak cyber-safety . These are reported findings from researchers, not independently verified conclusions in the source.

According to The Straits Times, TeamT5 said it had obtained scripts and logs showing AI tools being used throughout attacks. The report describes three examples: a group called Grimfengxi allegedly used DeepSeek to create exploit code; a group called Huapi allegedly used a Chinese AI model that researchers believed was DeepSeek against a Taiwanese company’s email system; and a group called Teleboyi allegedly used the platform to collect 1,000 internet IP addresses and map a company’s domains. The source does not provide enough technical detail to assess the success or full scope of those operations.

The Straits Times also reports that Chinese hacking groups used other models. CyCraft said a company selling hacking software used ChatGPT during an attack on a Western think tank. After hackers obtained an employee’s local Signal database from a compromised computer, screenshots reviewed by Bloomberg News allegedly showed them consulting ChatGPT to help build a module intended to decrypt it. TeamT5 separately said a group called Slime22 used Claude Code to conduct lateral movement inside a Taiwanese technology company after installing Kali, a penetration-testing platform. The source says the group bypassed safeguards by posing as an engineer conducting authorized security tests.

The report says researchers found a public shared drive containing thousands of Chinese-language screenshots, including images taken as recently as February, that depicted a roughly 10-person startup developing hacking tools for sale. The tools allegedly cost between 300,000 yuan and 500,000 yuan, and the report says at least four hacking groups were customers. The Straits Times says activity linked to one group overlapped with operations publicly attributed to Mustang Panda, which the U.S. Justice Department describes as backed by the Chinese government. DeepSeek, China’s embassy in Washington and China’s Ministry of Foreign Affairs did not respond to requests for comment, according to the report.

來源詳情: straitstimes.com ↗

為什麼這很重要

The report indicates that AI-assisted cyber operations do not require the most advanced models to scale. Low-cost, customizable models with comparatively weak cybersecurity may help experienced attackers automate routine work and develop malicious software, potentially increasing the volume and speed of attacks against companies and institutions.

The central significance is operational scale. The Straits Times’ account suggests that attackers may use relatively ordinary language models to automate reconnaissance, generate code and perform other repetitive tasks, leaving experienced operators to coordinate campaigns and make higher-level decisions. That matters because the security impact of AI may come less from autonomous, frontier-model behavior than from making established intrusion techniques faster, cheaper or easier to repeat. The reported doubling of attacks is attributed to TeamT5 and is not independently confirmed by the source.

DeepSeek’s reported appeal also illustrates how safety controls, price and customization can influence abusive use. Researchers told The Straits Times that Chinese hackers preferred DeepSeek in part because it was inexpensive and had weaker cyber than some Western services. The source does not establish that DeepSeek caused any specific breach, that its safeguards are universally weaker, or that it was the model used in every cited incident. It does show why model availability and abuse prevention are becoming security concerns alongside model capability.

The reported use of commercial Western tools complicates a simple national or technological divide. The Straits Times says Chinese-linked actors also used ChatGPT and Claude Code, despite provider restrictions or safeguards. In the Claude Code case, TeamT5 said attackers impersonated a legitimate security tester to bypass protections. In the ChatGPT case, the source describes assistance with a decryption-related software module but does not establish whether the module worked or whether the model supplied the decisive technical knowledge. Those limits are important when assessing the practical effect of AI assistance.

For defenders, the implication is that model use may be only one component of a broader intrusion chain. The reported examples involve compromised systems, local data, reconnaissance, exploit development, penetration-testing tools and lateral movement. Logs, prompts or screenshots may help investigators identify AI assistance, but the source does not say how reliably such evidence can be collected or authenticated. Organizations therefore cannot assume that detecting a model’s fingerprints will be sufficient; the article supports attention to conventional access controls, endpoint monitoring and investigation of unusual automation, while leaving the effectiveness of specific defenses unresolved.

Interactive Mechanism

互動機制:它實際上是如何運作的

以互動方式探索這項發展背後的基礎技術。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
互動式概念檢查+10 Points
AI Models Explained Quiz

Which component of an AI application is the machine-learning model itself?

接下來看什麼

Further evidence is needed to establish how often DeepSeek or other models are used in real-world attacks, how much human expertise remains necessary, and whether AI materially improves outcomes. Watch for technical disclosures, affected organizations’ investigations, model-provider abuse reports and evidence that providers’ safeguards are being bypassed or strengthened.

The first question is whether TeamT5, CyCraft or affected organizations publish fuller technical evidence. The Straits Times reports that researchers had scripts, logs and screenshots, but the source does not include the artifacts, indicators of compromise, attack timelines or independent forensic findings. Those details would help distinguish direct model use from human-written tooling, establish whether the cited groups achieved their objectives and clarify how much of the reported increase in attacks can be attributed to AI.

Watch for confirmation from model providers and governments. DeepSeek did not respond to The Straits Times’ request for comment, while Anthropic also did not answer questions. OpenAI said it was committed to identifying, preventing and disrupting abuse of its models. The article does not report any new restriction or technical change by DeepSeek, OpenAI or Anthropic in response to these findings. Public provider investigations could clarify account controls, abuse-detection methods and whether the models’ logs support or contradict the researchers’ account.

A second area to monitor is the role of model capability and cost. The report says researchers had not recorded an incident involving Moonshot’s Kimi K3 and believed it was too expensive for hackers to run, while describing DeepSeek as sufficiently capable and cheaper. That is a researcher assessment, not a comparative study. Further evidence would be needed to determine whether cost, access, , model quality or familiarity is the main factor shaping attackers’ choices.

Finally, the report connects this story to a previous Anthropic disclosure that Chinese state-backed hackers used Claude Code in September 2025 to target 30 entities, which Anthropic characterized as the first documented large-scale cyberattack executed without substantial human intervention. The current article does not independently verify that earlier claim or establish that the newly described DeepSeek activity is autonomous. Future reporting should separate human-directed assistance, partial automation and genuinely autonomous operations, because those categories carry different risks and require different defensive and policy responses.

相關指引和測驗

人工智慧模型解釋人工智慧代理人工智慧安全AI 倫理測試你所知道的—嘗試免費的人工智慧測驗在我們的詞彙表中尋找人工智慧術語關注AI監管追蹤器
覺得有用嗎?