AI Tools Fuel Surge in Chinese State Hacking Operations
Reported by The Decoder: Taiwanese cybersecurity firm warns that AI tools have more than doubled Chinese state-backed cyberattacks. Analysis and context written by TickrWire.
Taiwanese cybersecurity firm TeamT5 reports that Chinese state-backed hacking groups have more than doubled their attack frequency after adopting AI models such as DeepSeek.

- Chinese state-backed hacking groups have more than doubled their attack frequency since adopting AI tools.
- DeepSeek is heavily favored by these operators due to its strong performance and low security guardrails.
- Specific hacking collectives used AI for writing exploit code, mapping domains, and building data decryption modules.
- A UK AI Safety Institute study shows open models are rapidly closing the cyber capability gap.
State-backed cyber espionage and hacking collectives operating out of China have significantly increased their operational tempo, more than doubling their assault frequency. According to findings released by the Taiwanese cybersecurity organization TeamT5, this escalation directly correlates with the integration of artificial intelligence models into daily offensive workflows. Intelligence gathered by the security firm highlights that malicious actors are increasingly turning to automated systems to streamline routine tasks, accelerate reconnaissance, and draft malicious software payloads. Among the available options, the DeepSeek ecosystem has emerged as a preferred utility for these state-sponsored entities due to a combination of high performance capabilities and minimal security restrictions. Analysts note that these characteristics allow hostile operators to bypass typical limitations that would normally hinder automated exploit generation.
Specific threat actor operations illustrate the diverse ways artificial intelligence is being embedded into cyber campaigns. The hacking collective known as Grimfengxi utilized the DeepSeek infrastructure to author complex exploit code targeting victim environments. Another group, designated as Huapi, similarly relied on domestic Chinese artificial intelligence technology, which researchers assess to be DeepSeek. In a different campaign, the group Teleboyi leveraged the platform to gather target IP addresses and map network domains prior to launching deeper intrusions. Beyond domestic alternatives, Western tools also surfaced in distinct operations. Investigators from CyCraft uncovered evidence indicating that hackers incorporated OpenAI technology to construct a specialized decryption module designed to extract data from a Signal messaging database. Additionally, TeamT5 observed a threat group called Slime22 utilizing advanced coding assistants from Anthropic during a lateral movement phase inside a compromised Taiwanese organization.
The broader implications of these developments extend beyond individual group tactics, touching on an accelerating convergence between large language models and offensive cyber capabilities. While current threat actor usage focuses heavily on augmenting human operators with routine tasks and basic code generation, empirical assessments indicate that the underlying technology is evolving rapidly. A recent evaluative study conducted by the United Kingdom AI Safety Institute demonstrated that the offensive cyber capabilities associated with open-source and open-weight models have advanced substantially in a short timeframe. Despite these rapid improvements, independent testing reveals that fully autonomous attack execution still lags behind the most sophisticated Western frontier systems by a margin of several months.
The reliance on AI for cyber operations introduces significant challenges for defenders worldwide. By lowering the technical barrier to entry and dramatically increasing the speed of reconnaissance and exploit development, malicious groups can mount larger and more frequent campaigns with fewer resources. As these technologies become more accessible and refined, security teams face an escalating volume of automated threats that continuously probe infrastructure for vulnerabilities. Organizations must adapt their defense strategies to account for the speed and scale made possible by machine learning integration, while policymakers grapple with the dual-use nature of advanced language models and the difficulty of implementing effective guardrails across global markets.
Highlights the critical need to design and evaluate developer tools and models with robust security guardrails against misuse.
Signals a dramatic increase in the volume and frequency of automated cyber threats targeting enterprise networks.
Emphasizes the rising strategic importance of AI-driven cybersecurity defense tools as offensive capabilities expand.
- exploit code
- Software designed to take advantage of a security flaw in a computer system or application.
- lateral movement
- Techniques used by attackers to move deeper through a network after initial compromise.
SecurityInstinct’s powerful AI assistant is raising privacy and security concerns
SecurityAI chatbots regularly link pregnant users to anti-abortion websites without disclosure
SecurityFlock CEO calls for ‘compromise’ as surveillance company faces growing backlash
SecurityIs it legal to train AI models on copyrighted books? It’s complicated
SecurityHow China's gray market sells Claude tokens at a fraction of the price
RoboticsI spent a day at a robot “carnival” in Shanghai. Here’s what I saw.
A recent robotics festival in Shanghai highlighted China's rapid commercial progress in humanoid systems, where local firms now dominate global delivery numbers.

Disrupting a new covert influence campaign from Russia
OpenAI blocked Russian ChatGPT accounts that were used to push a fabricated Israeli think‑tank and a pro‑Russia sovereignty index, exposing a covert influence operation.
Open SourceFastino Releases GLiNER2.5: A Boundary-Prediction Architecture That Removes Span Enumeration From Information Extraction
Fastino has released GLiNER2.5, replacing traditional span enumeration with boundary prediction to enable efficient, long-context information extraction on consumer hardware.
BusinessTrump bought SpaceX shares two weeks after blockbuster IPO
President Donald Trump purchased up to fifty thousand dollars in SpaceX stock shortly after the company's initial public offering, according to financial disclosures.
BusinessAmjad Masad, CEO and co-founder of Replit, joins the Disrupt Stage at TechCrunch Disrupt 2026
Replit co-founder and CEO Amjad Masad is scheduled to speak at TechCrunch Disrupt 2026, discussing the evolving software landscape and his company's rapid financial ascent amid the artificial intelligence boom.
AI ResearchPew study confirms sharp rise of AI-written text on the web since ChatGPT's launch
A Pew Research Center study reveals that over a third of English language web pages published since late 2022 show indicators of machine authorship.