AI is becoming part of the operating toolkit for state-backed hacking groups from China, according to Taiwanese security firm TeamT5. The firm says attacks have more than doubled since these groups began using AI for routine work and malware development.
The report points to a shift that is less about one dramatic new technique and more about acceleration. Tools such as DeepSeek, ChatGPT and Claude Code are being used across different parts of the hacking workflow, from writing exploit code to moving through company systems.
TeamT5 says attack volume has surged
TeamT5’s central warning is direct: state-backed hacking groups from China have more than doubled their attacks since they started bringing AI into common cyber operations. The source attributes that increase to the use of AI for routine tasks and malware development.
That matters because routine work is a large part of cyber operations. When attackers can use AI to handle repetitive or technical steps faster, the overall pace of activity can rise even if the underlying goals remain the same.
TeamT5 chief analyst Charles Li singled out DeepSeek as a favored tool among Chinese hackers. He said DeepSeek is especially popular
because it’s relatively powerful with very low cyber guardrails
That explanation helps frame why one model appears so often in the reported cases. The issue is not simply that AI exists, but that some tools may be useful enough for cyber work while offering fewer barriers to harmful use.
How specific groups used AI tools
The source names several groups and links them to different AI-assisted activities. Grimfengxi used DeepSeek to write exploit code. Huapi relied on a Chinese model that was likely to be DeepSeek.
Teleboyi used DeepSeek for reconnaissance-style tasks, including collecting IP addresses and mapping domains. These steps are basic, but they are also important because they help attackers understand what systems exist and where to focus attention.
ChatGPT appears in at least one reported case. Security firm CyCraft found evidence that hackers used it to build a decryption module for a Signal database.
TeamT5 also said Slime22 used Anthropic's Claude Code to move through the systems of a Taiwanese company. That detail shows that the reported AI use was not limited to one provider, one model family or one stage of an attack.
DeepSeek stands out in the reported activity
DeepSeek is the most prominent tool in the cases described by TeamT5. It was connected to exploit code, a likely Chinese-model use by Huapi and IP address and domain mapping by Teleboyi.
The pattern described in the source suggests that attackers are using AI where it can reduce manual effort. Writing exploit code, collecting infrastructure details and supporting malware development are different tasks, but they share a common feature: each can benefit from speed, technical fluency and automation.
The source does not say that DeepSeek is the only tool involved. It also does not say that AI alone is responsible for every attack. The narrower and more important point is that AI has become useful enough to be integrated into the work of named hacking groups.
Open models are improving, but autonomy still lags
The article also cites a study by the UK AI Safety Institute, which found that the cyber capabilities of open models have jumped sharply. That adds a broader technical backdrop to the specific cases reported by TeamT5.
Even so, the source draws a boundary around what these systems can do. For fully autonomous attacks, open models still trail Western frontier models like Claude Mythos by several months.
That distinction is important. The reported threat is not necessarily a future in which every attack runs independently from start to finish. The immediate concern is that AI tools are already useful inside parts of the cyberattack process.
Why this changes the security picture
The practical implication is that defenders may face more activity, faster iteration and a wider spread of AI-assisted techniques. TeamT5’s warning is about scale as much as sophistication: the number of attacks has more than doubled after these groups began using AI for routine tasks and malware development.
The named examples also show how varied the use cases can be:
- Grimfengxi used DeepSeek to write exploit code.
- Huapi used a Chinese model likely to be DeepSeek.
- Teleboyi used DeepSeek to collect IP addresses and map domains.
- Hackers used ChatGPT to build a decryption module for a Signal database, according to CyCraft.
- Slime22 used Anthropic's Claude Code to move through the systems of a Taiwanese company, TeamT5 said.
Taken together, these cases show AI moving from novelty into practical cyber operations. The source does not claim that AI replaces hackers. It shows something more immediate: AI can help them perform familiar tasks more efficiently.
For cybersecurity teams, that is enough to matter. A tool that speeds up reconnaissance, coding or movement through systems can change how often attacks appear and how quickly attackers can adapt. TeamT5’s warning is therefore less about a single model and more about the operational advantage that AI can give to groups already active in cyber campaigns.