Cybersecurity2 mins read

AI Tools Linked to Surge in Chinese State-Backed Cyberattacks, TeamT5 Warns

Taiwanese security firm TeamT5 says Chinese state-backed hacking groups have more than doubled attacks since using AI models such as DeepSeek for exploit code, network scanning, and other cyber tasks.

China flag visual associated with The Decoder article on AI-enabled cyberattacks
Image credits:The Decoder

TeamT5 Says AI Use Has Sharply Increased Attack Volume

Taiwanese security firm TeamT5 warns that Chinese state-backed hacking groups have more than doubled their attacks since adopting AI for routine cyber tasks and malware development. The reported shift centers on tools that can help write exploit code, scan networks, and speed up reconnaissance.

The takeaway for defenders is direct: AI is not only a productivity tool for legitimate teams, but also a force multiplier for attackers. Security programs should assume faster probing, quicker tooling, and more frequent attempts from sophisticated groups.

DeepSeek, ChatGPT, and Claude Code Appear in Reported Cases

According to the article, DeepSeek is especially popular among Chinese hackers, with TeamT5 chief analyst Charles Li saying it is “relatively powerful with very low cyber guardrails.” TeamT5 said the group Grimfengxi used DeepSeek to write exploit code, Huapi relied on a Chinese model likely to be DeepSeek, and Teleboyi used the platform to collect IP addresses and map domains.

Other tools also appeared in reported activity. CyCraft found evidence that ChatGPT was used to build a decryption module for a Signal database, while TeamT5 said Slime22 used Anthropic's Claude Code to move through the systems of a Taiwanese company.

Open Models Are Catching Up in Cyber Capability

The article also cites a UK AI Safety Institute study finding that the cyber capabilities of open models have jumped sharply. For fully autonomous attacks, those models still trail Western frontier models such as Claude Mythos by several months.

That gap matters because it may narrow over time. Organizations should treat AI-assisted cyber capability as a moving target, not a fixed threat category.

What Security Teams Should Prioritize Now

The reported uses point to practical areas of attention: exploit-code development, network scanning, IP collection, domain mapping, and movement through internal systems. Teams should review how quickly they detect and respond to these behaviors, especially when activity appears automated or unusually fast.

The clearest implication is that routine defensive hygiene becomes more urgent when attackers can automate routine offensive work. Exposure management, monitoring, and incident response workflows need to keep pace with faster AI-assisted operations.

Discover More

    U.S. Coast Guard troops scaling a ladder onto a vessel
    Hacked Tankers Boarded

    The FBI and Coast Guard investigated compromised tanker networks near the U.S. coast.

    CybersecurityShipping
    Warning message, computer notification on screen
    Claude Used in OpenAI Hack

    A bug-bounty test shows how AI tools can accelerate vulnerability discovery and raise new security questions for AI labs.

    AI SecurityOpenAI
    Robot scientists threat illustration for AI existential risk story
    Mathematicians Warn on AI Risk

    Royal Society fellows say advanced AI risks demand urgent public and government attention.

    AI SafetyArtificial Intelligence