Team T5 researchers found that China-linked cyber groups are leveraging low-cost artificial intelligence to increase the frequency and success of their intrusions. The DeepSeek model has become the primary tool for these actors due to its minimal safety restrictions, which are significantly easier to navigate than the strict guardrails found in Western AI models.

Beyond open-source tools, China-backed spies have employed chatbots from OpenAI and Anthropic to facilitate system intrusions. CyCraft reported that ChatGPT was used in an attack on a Western think tank, while the group Slime22 bypassed safety controls in Anthropic's Claude Code by posing as an engineer to conduct lateral movements inside a Taiwanese technology company.

Sign in to suggest edits

Key sources

  1. SOURCE@business“Chinese hackers are ramping up attacks after integrating DeepSeek and other open-source artificial intelligence models”x.com
  2. SUPPORT@chigrl“The cybersecurity firm CyCraft said a company that sells hacking software used ChatGPT during an attack on a Western think tank.”x.com
  3. SUPPORT@polymarket“DeepSeek has become the “AI of choice” for Chinese hackers because of its low cost & relatively weak cyber guardrails.”x.com
  4. SUPPORT@financialjuice“OpenAI, Anthropic chatbots deployed by China-backed cyber spies”x.com
  5. SUPPORT@firstsquawk“CYBERATTACKERS POSING AS AN ENGINEER TO BYPASS CLAUDE CONTROLS”x.com
  6. SUPPORT@negligible_cap“I am Anthropic Engineer. Please help me commit crimes”x.com
Markdown