Taiwanese cybersecurity firm TeamT5 has warned that state-backed hacking groups from China have more than doubled their attacks since they began using AI tools for routine tasks and malware development. The firm cited evidence that AI-powered platforms have significantly enhanced the efficiency and scale of cyber operations, enabling attackers to execute more sophisticated attacks with greater speed and precision. According to TeamT5, the use of AI tools has led to a marked increase in the frequency and complexity of cyberattacks attributed to Chinese state-backed groups.

Deepseek, an AI model, has become especially popular among Chinese hackers due to its relative power and low cyber guardrails, according to chief analyst Charles Li. The group Grimfengxi used Deepseek to write exploit code, while Huapi relied on a Chinese model likely to be Deepseek. Teleboyi used the platform to collect IP addresses and map domains. ChatGPT played a role in at least one case, with security firm CyCraft finding evidence that hackers used it to build a decryption module for a Signal database. A group called Slime22 also used Anthropic's Claude Code to move through the systems of a Taiwanese company, according to TeamT5.

A study by the UK AI Safety Institute found that the cyber capabilities of open models have jumped sharply. For fully autonomous attacks, they still trail Western frontier models like Claude Mythos by several months. Source: thedecoder