25 August 2026
Chinese hackers double attacks using DeepSeek AI
First reported
The Decoder, The Neuron and 1 other ran this on , all on the same day.
- State-backed Chinese hacking groups more than doubled their cyberattacks after incorporating DeepSeek, an open-source AI model, into malware development and reconnaissance operations.
- DeepSeek attracted hackers because it is powerful yet has minimal safety restrictions, unlike commercial models with stronger safeguards built in.
- Specific groups used DeepSeek to write malicious code, map network targets, and collect IP addresses. Other groups used ChatGPT and Anthropic's Claude for related tasks.
Where they differ
Both newsletters reported the same core fact, but The Rundown AI emphasized that cheaper models with fewer safeguards pose harder security challenges than advanced commercial models, while The Neuron stuck to what hackers actually did with the tool.
Chinese state-tied hacking groups have more than doubled their cyberattacks after integrating open-source AI models like DeepSeek into their operations, according to Taiwanese research firm TeamT5. The newsletter highlights that DeepSeek's low cost and loose guardrails make it the preferred choice for attackers, suggesting cheaper models with fewer safeguards may pose harder security challenges than advanced commercial models.
Chinese state-backed hackers more than doubled their attack volume after incorporating DeepSeek into malware development and reconnaissance, according to researchers.
Reported by The Decoder