Chinese state-backed hacking groups have more than doubled their cyberattack volume since adopting AI models to automate exploit development and network reconnaissance, according to TeamT5, a Taiwanese cybersecurity firm. The attackers leverage DeepSeek, ChatGPT, and Anthropic's Claude Code to write malicious code and execute reconnaissance at scale, fundamentally changing the economics of state-sponsored cyber operations.
The shift represents a watershed moment in cyber warfare. Human-written exploits require specialized expertise and time. AI-generated code eliminates both constraints. Attackers no longer need armies of skilled engineers to probe networks, identify vulnerabilities, and craft payloads. A single operator can now deploy dozens of reconnaissance campaigns simultaneously, testing different attack vectors against multiple targets in parallel. This parallelization effect explains the doubling in observed attacks.
TeamT5's findings align with emerging research from the UK that demonstrates open-source AI models now approach the cyber capabilities of proprietary systems. This convergence matters because open models like DeepSeek operate without the safety guardrails major vendors implement. DeepSeek, developed by Chinese AI company High-Flyer, has already drawn scrutiny for minimal content filtering. State actors can run it locally without sending prompts through external APIs, eliminating detection vectors that cloud-based systems create.
The attack types reveal a pattern. Chinese groups use AI to generate initial access exploits, automate vulnerability scanning, and craft social engineering payloads tailored to specific targets. The automation bypasses traditional defenses that rely on signature matching or anomaly detection of human-authored code. Each AI-generated variant looks different enough to evade static analysis.
ChatGPT and Claude Code appear in the targeting primarily for their English-language capability. Chinese attackers use these systems to craft convincing English-language phishing messages and social engineering lures targeting Western organizations. The cultural and linguistic authenticity improves success rates. OpenAI and Anthropic already prohibit such uses in their terms of service, but enforcement remains difficult when attackers use proxies or operate from jurisdictions where terms carry no legal weight.
The doubling in attacks accelerates an existing trend. Ransomware groups, Iranian hacking units, and Russian-affiliated operators began experimenting with LLMs in 2023. What TeamT5 documents is the transition from experimentation to operational deployment. State actors have integrated AI into their standard workflow. Budget allocation and planning now assume AI availability.
This escalation creates pressure on defensive operations. Security teams already struggle with alert fatigue and analyst shortage. The doubling in attack volume exacerbates both problems. Machine-generated attacks also consume more compute resources to analyze, as each variant requires investigation. Defenders cannot assume patterns they saw yesterday will repeat.
The findings highlight the dual-use dilemma facing AI vendors. Restricting capabilities invites criticism about censorship. Enabling broad deployment of powerful models without safeguards directly empowers adversaries. DeepSeek's approach of minimal restrictions positions it as a preferred tool for malicious actors despite its legitimate uses.
Mitigation requires layered response. Organizations need behavioral detection systems that catch anomalous network reconnaissance regardless of exploit source. Security teams should assume all internal networks face continuous probing. Threat intelligence sharing between allied nations becomes more urgent when attack volume climbs this sharply. The US, UK, and Taiwan can coordinate defensive measures more effectively if they share patterns of AI-generated attacks early.
The long-term concern extends beyond doubled attack volume. As AI models improve, the sophistication gap between attack and defense narrows. Defenders cannot match attackers' operational tempo indefinitely.
