SecurityAug 25, 2026, 8:40 AM

AI Tools Fuel Surge in Chinese State Hacking Operations

TickrWire Editorial Desk·Aug 25, 2026, 8:40 AM·2 min read AI-assisted, human-reviewed

Reported by The Decoder: Taiwanese cybersecurity firm warns that AI tools have more than doubled Chinese state-backed cyberattacks. Analysis and context written by TickrWire.

30-second summary

Taiwanese cybersecurity firm TeamT5 reports that Chinese state-backed hacking groups have more than doubled their attack frequency after adopting AI models such as DeepSeek.

TickrWire
AI Tools Fuel Surge in Chinese State Hacking Operations
Key takeaways
  • Chinese state-backed hacking groups have more than doubled their attack frequency since adopting AI tools.
  • DeepSeek is heavily favored by these operators due to its strong performance and low security guardrails.
  • Specific hacking collectives used AI for writing exploit code, mapping domains, and building data decryption modules.
  • A UK AI Safety Institute study shows open models are rapidly closing the cyber capability gap.
Full story

State-backed cyber espionage and hacking collectives operating out of China have significantly increased their operational tempo, more than doubling their assault frequency. According to findings released by the Taiwanese cybersecurity organization TeamT5, this escalation directly correlates with the integration of artificial intelligence models into daily offensive workflows. Intelligence gathered by the security firm highlights that malicious actors are increasingly turning to automated systems to streamline routine tasks, accelerate reconnaissance, and draft malicious software payloads. Among the available options, the DeepSeek ecosystem has emerged as a preferred utility for these state-sponsored entities due to a combination of high performance capabilities and minimal security restrictions. Analysts note that these characteristics allow hostile operators to bypass typical limitations that would normally hinder automated exploit generation.

Specific threat actor operations illustrate the diverse ways artificial intelligence is being embedded into cyber campaigns. The hacking collective known as Grimfengxi utilized the DeepSeek infrastructure to author complex exploit code targeting victim environments. Another group, designated as Huapi, similarly relied on domestic Chinese artificial intelligence technology, which researchers assess to be DeepSeek. In a different campaign, the group Teleboyi leveraged the platform to gather target IP addresses and map network domains prior to launching deeper intrusions. Beyond domestic alternatives, Western tools also surfaced in distinct operations. Investigators from CyCraft uncovered evidence indicating that hackers incorporated OpenAI technology to construct a specialized decryption module designed to extract data from a Signal messaging database. Additionally, TeamT5 observed a threat group called Slime22 utilizing advanced coding assistants from Anthropic during a lateral movement phase inside a compromised Taiwanese organization.

The broader implications of these developments extend beyond individual group tactics, touching on an accelerating convergence between large language models and offensive cyber capabilities. While current threat actor usage focuses heavily on augmenting human operators with routine tasks and basic code generation, empirical assessments indicate that the underlying technology is evolving rapidly. A recent evaluative study conducted by the United Kingdom AI Safety Institute demonstrated that the offensive cyber capabilities associated with open-source and open-weight models have advanced substantially in a short timeframe. Despite these rapid improvements, independent testing reveals that fully autonomous attack execution still lags behind the most sophisticated Western frontier systems by a margin of several months.

The reliance on AI for cyber operations introduces significant challenges for defenders worldwide. By lowering the technical barrier to entry and dramatically increasing the speed of reconnaissance and exploit development, malicious groups can mount larger and more frequent campaigns with fewer resources. As these technologies become more accessible and refined, security teams face an escalating volume of automated threats that continuously probe infrastructure for vulnerabilities. Organizations must adapt their defense strategies to account for the speed and scale made possible by machine learning integration, while policymakers grapple with the dual-use nature of advanced language models and the difficulty of implementing effective guardrails across global markets.

Why this matters
Developers

Highlights the critical need to design and evaluate developer tools and models with robust security guardrails against misuse.

Businesses

Signals a dramatic increase in the volume and frequency of automated cyber threats targeting enterprise networks.

Investors

Emphasizes the rising strategic importance of AI-driven cybersecurity defense tools as offensive capabilities expand.

Glossary
exploit code
Software designed to take advantage of a security flaw in a computer system or application.
lateral movement
Techniques used by attackers to move deeper through a network after initial compromise.
Sources · 1
Read next
More stories
I spent a day at a robot “carnival” in Shanghai. Here’s what I saw.Robotics

I spent a day at a robot “carnival” in Shanghai. Here’s what I saw.

A recent robotics festival in Shanghai highlighted China's rapid commercial progress in humanoid systems, where local firms now dominate global delivery numbers.

Disrupting a new covert influence campaign from Russia

Disrupting a new covert influence campaign from Russia

OpenAI blocked Russian ChatGPT accounts that were used to push a fabricated Israeli think‑tank and a pro‑Russia sovereignty index, exposing a covert influence operation.

Fastino Releases GLiNER2.5: A Boundary-Prediction Architecture That Removes Span Enumeration From Information ExtractionOpen Source

Fastino Releases GLiNER2.5: A Boundary-Prediction Architecture That Removes Span Enumeration From Information Extraction

Fastino has released GLiNER2.5, replacing traditional span enumeration with boundary prediction to enable efficient, long-context information extraction on consumer hardware.

Trump bought SpaceX shares two weeks after blockbuster IPOBusiness

Trump bought SpaceX shares two weeks after blockbuster IPO

President Donald Trump purchased up to fifty thousand dollars in SpaceX stock shortly after the company's initial public offering, according to financial disclosures.

Amjad Masad, CEO and co-founder of Replit, joins the Disrupt Stage at TechCrunch Disrupt 2026Business

Amjad Masad, CEO and co-founder of Replit, joins the Disrupt Stage at TechCrunch Disrupt 2026

Replit co-founder and CEO Amjad Masad is scheduled to speak at TechCrunch Disrupt 2026, discussing the evolving software landscape and his company's rapid financial ascent amid the artificial intelligence boom.

Pew study confirms sharp rise of AI-written text on the web since ChatGPT's launchAI Research

Pew study confirms sharp rise of AI-written text on the web since ChatGPT's launch

A Pew Research Center study reveals that over a third of English language web pages published since late 2022 show indicators of machine authorship.