Technology

Chinese Hackers More Than Double Attack Activity With AI

Taiwanese cybersecurity researchers say China-linked hacking groups have sharply increased their activity after adopting AI tools such as DeepSeek for reconnaissance, vulnerability research and other routine tasks.

Chinese state-linked hacking groups have reportedly more than doubled their cyberattack activity after incorporating artificial-intelligence tools into their operations, according to Taiwanese threat-intelligence firm TeamT5. Researchers say AI is helping attackers automate time-consuming tasks, allowing them to examine potential targets and process technical information much faster than before.

DeepSeek has reportedly become particularly popular among these groups because it is relatively inexpensive, customizable and accessible compared with some more tightly restricted frontier AI systems. TeamT5 researchers have observed suspected Chinese-speaking groups using AI for activities including reconnaissance, vulnerability analysis and code-related work. However, the researchers caution that identifying exactly which AI model was responsible for every individual operation can be difficult.

The development demonstrates how AI can change the scale and economics of cyberattacks. Tasks that previously required considerable time from human operators can increasingly be assisted by automated systems. In one documented investigation, researchers found AI being used to examine large numbers of exposed systems and narrow potential targets. Importantly, however, independent analysis found that the autonomous AI activity did not necessarily result in successful compromises; confirmed intrusions in that campaign were associated with human operators.

The trend is part of a broader shift toward AI-assisted cyber operations. Researchers have recently documented attacks involving multiple AI agents working together to perform reconnaissance, evaluate vulnerabilities and coordinate different stages of an operation. Such systems could potentially allow attackers to operate more quickly and at greater scale, increasing pressure on organizations that still rely heavily on human-led security monitoring.

For cybersecurity teams, the development reinforces the importance of rapid patching, strong access controls and continuous monitoring. The biggest concern is not necessarily that AI can independently carry out every stage of an attack, but that it can reduce the time, cost and expertise required for certain tasks. As attackers adopt these technologies, security researchers are increasingly calling for defenders to use AI as well—turning the technology into a tool for detecting suspicious activity and strengthening defenses rather than allowing attackers to gain the advantage.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button