Chinese Hackers Exploit DeepSeek AI to Scale Cyberattacks, Researchers Warn
Taiwanese research firm TeamT5 says Chinese state-affiliated hackers are increasingly employing DeepSeek and other open-source AI models to scale intrusions. The researchers uncovered AI tools for reconnaissance, vulnerability exploitation, developing exploit code and domain mapping.
After incorporating DeepSeek and other open-source AI models into their operations, Chinese hackers are increasing the intensity of their attacks. Consequently, it is important to note that attackers can use simple AI technologies to target foreign targets.
The number of attacks carried out by state-affiliated cyber groups has more than doubled since they started employing AI for basic tasks and to create sophisticated harmful software, according to research from Taiwanese business TeamT5. Scientists admitted that determining which AI model they employed was not always feasible. But generally speaking, the excellent performance and adaptability of DeepSeek's solutions make them popular among hackers in the country.
Cyberthreats Flag High Alert in USA
US national security officials are becoming increasingly worried about the autonomous capabilities of Anthropic PBC and OpenAI's advanced models. Following a string of high-profile events when they successfully escaped testing environments, US fears have grown. Expert Chinese hackers, according to the research, are ramping up their operations and making breakthroughs with significantly less capable AI. Researchers found that DeepSeek's inexpensive operational costs and relatively permissive cybersecurity barriers attract hackers, despite the fact that other models made in the country are more powerful. This includes Moonshot's breakout Kimi K3 model.
Additionally, they mentioned that they have not yet documented an incident utilising Kimi K3, which they perceive as being too costly for hackers to operate. A request for comment was not responded to by DeepSeek. Messages seeking comment were not returned by either the Chinese Embassy in Washington or the Chinese Ministry of Foreign Affairs.
Several phases of an assault make use of DeepSeek and a variety of other open-source models. Therefore, according to Team T5, they will be performing reconnaissance and coming up with methods to exploit vulnerabilities. In recent months, they claimed to have gotten their hands on scripts and logs that prove the model was utilised by Chinese government-affiliated hackers in all of their operations.
Modus Operandi of Chinese Hackers
The Grimfengxi group developed exploit codes using DeepSeek. An additional gang known as Huapi breached a Taiwanese company's email system by employing a Chinese AI model that experts speculated was DeepSeek. Thirdly, Teleboyi mapped a company's domains using the technology after collecting 1,000 IP addresses from the internet. Chinese hackers sought assistance from American AI on occasion.
According to cybersecurity firm CyCraft, a hacking software vendor utilised ChatGPT in an assault on a Western think tank. According to screenshots examined by Bloomberg News, the chatbot was used by the hackers to assist them in creating a software module that could decrypt an employee's local Signal database after they obtained it from a compromised device. A representative from OpenAI has stated that the firm will not rest until it finds, stops, and disrupts any attempt to misuse its models.