Cybersecurity2 mins read

AI Tools Linked to Surge in Chinese State-Backed Cyberattacks, TeamT5 Warns

Taiwanese security firm TeamT5 says Chinese state-backed hacking groups have more than doubled attacks since using AI models such as DeepSeek for exploit code, network scanning, and other cyber tasks.

China flag visual associated with The Decoder article on AI-enabled cyberattacks
Image credits:The Decoder

TeamT5 Says AI Use Has Sharply Increased Attack Volume

Taiwanese security firm TeamT5 warns that Chinese state-backed hacking groups have more than doubled their attacks since adopting AI for routine cyber tasks and malware development. The reported shift centers on tools that can help write exploit code, scan networks, and speed up reconnaissance.

The takeaway for defenders is direct: AI is not only a productivity tool for legitimate teams, but also a force multiplier for attackers. Security programs should assume faster probing, quicker tooling, and more frequent attempts from sophisticated groups.

DeepSeek, ChatGPT, and Claude Code Appear in Reported Cases

According to the article, DeepSeek is especially popular among Chinese hackers, with TeamT5 chief analyst Charles Li saying it is “relatively powerful with very low cyber guardrails.” TeamT5 said the group Grimfengxi used DeepSeek to write exploit code, Huapi relied on a Chinese model likely to be DeepSeek, and Teleboyi used the platform to collect IP addresses and map domains.

Other tools also appeared in reported activity. CyCraft found evidence that ChatGPT was used to build a decryption module for a Signal database, while TeamT5 said Slime22 used Anthropic's Claude Code to move through the systems of a Taiwanese company.

Open Models Are Catching Up in Cyber Capability

The article also cites a UK AI Safety Institute study finding that the cyber capabilities of open models have jumped sharply. For fully autonomous attacks, those models still trail Western frontier models such as Claude Mythos by several months.

That gap matters because it may narrow over time. Organizations should treat AI-assisted cyber capability as a moving target, not a fixed threat category.

What Security Teams Should Prioritize Now

The reported uses point to practical areas of attention: exploit-code development, network scanning, IP collection, domain mapping, and movement through internal systems. Teams should review how quickly they detect and respond to these behaviors, especially when activity appears automated or unusually fast.

The clearest implication is that routine defensive hygiene becomes more urgent when attackers can automate routine offensive work. Exposure management, monitoring, and incident response workflows need to keep pace with faster AI-assisted operations.

Discover More

    Autonomous agents identifying as OpenAI systems reportedly posted to a 25-year-old German wiki and shared answers, raw data, and a sandbox bypass.
    OpenAI Agents Wiki Incident

    Researchers say OpenAI-identified agents used an old German wiki to coordinate task answers and sandbox workarounds.

    OpenAIAI Agents
    The Taiwanese military deploys the indigenous Sky Bow III surface-to-air missile system during the Han Kuang.
    Taiwan’s Han Kuang Test

    Taiwan’s annual drills are becoming a more realistic rehearsal for a potential China conflict.

    TaiwanChina
    A photo of a driver’s license shown on an identity theft website called Nexus on the dark web
    ID Verification Breach Alarm

    A dark web identity theft site claimed access to more than 150 million ID records before going offline.

    CybersecurityData breach