Chinese state-affiliated hacking groups have more than doubled the volume of their attacks since handing reconnaissance and malware development to open-source AI models, according to research published by TeamT5, a Taiwanese threat-intelligence firm.

“DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” Charles Li, TeamT5’s chief analyst, told Bloomberg. Western models, he said, are sought after but their guardrails require considerably more effort to bypass. The implication running through the research is that refusal behavior functions as an operating cost, and that attackers select models the way any other user does, weighing capability against the work required to get a usable answer out of it.

The firm attached specific groups to specific tasks. Grimfengxi used DeepSeek to write exploit code. Huapi ran a Chinese model against a Taiwanese company’s email system. Teleboyi tasked an AI with collecting 1,000 IP addresses and mapping corporate domains. A fourth group, Slime22, took the harder route and ran Claude Code while impersonating an authorized engineer, working around the safeguards rather than choosing a model without them.

Cost shaped the choice as much as compliance did. TeamT5 recorded no attacks using Moonshot’s Kimi K3, which it assessed as more capable but too expensive for the groups it tracks to run at volume. DeepSeek is cheap, customizable and permissive, a combination that is not the same as being the most capable model available, and for this kind of work capability appears not to be the binding constraint.

The tasks being delegated also say something about where the gains are coming from. Reconnaissance, domain mapping and exploit drafting are volume work, the parts of an intrusion that scale with labor rather than with skill. Automating them does not make an operator more sophisticated; it makes the same operator able to run more operations at once, which is what a doubling in attack volume without a corresponding jump in technique would look like.

The finding gives an empirical shape to an argument that has been running mostly on assertion. Z.AI held back GLM-5.3’s weights this month for a two-week safety review after its cyber capabilities grew faster than the company expected. OpenAI took a different structural approach, shipping a purpose-built cyber model behind identity verification and legal declarations rather than restricting the capability itself. TeamT5’s data suggests attackers are already sorting themselves by which model asks the fewest questions.

It also lands alongside evidence that the tooling is spreading beyond state programs. A North Korean group was found this month running open-weight models on its own attack servers, removing any dependency on a provider that could observe or cut off access. Five US agencies warned last week that attackers are using AI to write exploitation scripts against Siemens industrial controllers at water and power facilities.

Neither DeepSeek nor Chinese government officials responded publicly to TeamT5’s findings.

Sources: Bloomberg, Implicator

–
By the Control Plane Editorial Team