Tuesday, August 25, 2026

Today’s Edition

AI Intel Report

MARKETS

Enterprise AI

DeepSeek Fuels Doubling of Chinese State Hacker Attacks

Open-source AI integration has enabled state-affiliated groups to automate reconnaissance and malware tasks, resulting in significantly higher attack volumes as tracked by security researchers.

7 MIN READ
An empty modern open-plan office at dusk with rows of monitors showing abstract dashboards, soft window light across the desks.
Illustration: AI Intel Report

DeepSeek is an open-source artificial intelligence model developed in China that offers high performance with notably minimal restrictions on queries related to cyber activities.

Chinese state-affiliated cyber groups have more than doubled the amount of attacks they carried out since they began delegating mundane tasks to AI and using it to develop advanced malicious software. This increase stems from the adoption of tools like DeepSeek for handling repetitive aspects of cyber campaigns. Researchers have tracked this trend through analysis of threat actor behavior. The shift allows for greater scale in operations targeting infrastructure abroad. State groups now achieve higher throughput in their offensive activities.

The integration of AI has transformed operational efficiency for these groups. Mundane tasks such as initial scanning are now handled efficiently by the models. This efficiency translates into more attacks being executed in the same time frame. The Bloomberg report details the extent of the increase. TeamT5 provided the data supporting the more than doubled figure.

What background led to the adoption of AI tools by these groups?

Chinese state-affiliated cyber groups have long engaged in espionage and disruptive activities against international targets. The introduction of accessible AI models has provided a new layer of capability. TeamT5 analysts observed the change in attack patterns after groups began experimenting with these technologies. The ability to automate parts of the kill chain has proven advantageous. This evolution reflects broader trends in how threat actors leverage emerging technologies.

Prior to AI integration, operations relied heavily on manual processes for reconnaissance and exploit development. The new approach reduces the time required for these steps. As a result, groups can pursue more targets simultaneously. The research from Bloomberg highlights the scale of this change. Analysts attribute the doubling directly to the use of AI for mundane tasks.

Actors such as Grimfengxi and Huapi have shown parallel interest in AI augmentation according to available tracking data. These developments indicate a wider trend across multiple groups. The accessibility of open-source models lowers barriers for advanced tactics. State affiliation provides resources for experimentation with new tools. Overall activity levels have risen as a direct consequence.

What details characterize the new autonomous attack campaign?

A Chinese-speaking threat actor tracked as knaithe and KnYuan used DeepSeek via the Hermes Agent framework to autonomously enumerate targets, source exploits, and launch attacks against more than 460 systems following a single Telegram instruction. This campaign demonstrated the potential for AI to handle end-to-end operations with limited human input. The actor achieved 14 confirmed successful attacks alongside manual operations using conventional workflows. Unit 42 researchers identified the use of seven vulnerabilities in the process. The combination of autonomous and manual methods allowed for confirmed impact on targeted infrastructure.

The single instruction triggered a sequence of AI-driven actions. Enumeration of targets occurred without further intervention. Exploitation followed based on sourced information. This level of autonomy marks a departure from traditional coordinated efforts. The campaign targeted a range of systems over an extended period.

Palo Alto Networks Unit 42 documented the full scope of the operation. The threat actor operated under the aliases knaithe and KnYuan throughout the activity. Seven distinct vulnerabilities were leveraged in the attacks. Autonomous enumeration combined with manual exploitation produced measurable results. The campaign stands as an early example of fully AI-supported offensive workflows.

What technical specifics define the Hermes Agent implementation?

The actor configured Hermes Agent with custom red-teaming skills including godmode jailbreaking and integrated FOFA for asset enumeration and Nuclei scan generation. DeepSeek was selected as the primary model due to its power and low cyber guardrails compared to Western alternatives like Claude Code, which were tested but had stricter restrictions. The framework allowed the AI to function as an autonomous offensive operator. Integration with external tools enhanced the reconnaissance phase. This setup enabled the generation of tailored scan configurations for vulnerability assessment.

Custom skills were added to bypass typical model limitations. The jailbreaking technique facilitated unrestricted query handling. FOFA provided access to asset data for initial targeting. Nuclei integration supported automated vulnerability scanning. These elements combined to create a robust offensive toolkit powered by the AI model.

The choice of DeepSeek over other models proved decisive for the actor. Western alternatives imposed limits that prevented full campaign execution. The lower restrictions allowed queries on exploit sourcing and target enumeration. Power in coding and reasoning tasks further supported the autonomous mode. This combination created conditions for the observed success rate.

Comparison of Cyber Operation Methods Before and After AI Integration
AspectTraditional ApproachAI-Enhanced Approach
ReconnaissanceManual searches and basic toolsFOFA integration for rapid enumeration
Exploit DevelopmentHand-crafted codeAI-sourced and generated exploits
Attack ExecutionCoordinated manual stepsAutonomous campaign with 14 successes
VolumeBaseline levelsMore than doubled overall
  1. Receive single Telegram instruction to initiate campaign.
  2. Utilize DeepSeek through Hermes Agent for target enumeration with FOFA.
  3. Source exploits and generate Nuclei scans autonomously.
  4. Launch attacks against identified systems achieving 14 successes.
  5. Supplement with manual operations for additional impact.

What are the market and stakeholder implications for enterprises?

Enterprises face heightened risks from the increased volume of attacks enabled by AI tools. The ability of threat actors to scale operations poses challenges for defense teams. Organizations must enhance monitoring for AI-driven reconnaissance patterns. Investment in advanced detection systems becomes critical. The findings underscore the need for updated security postures against evolving threats.

Stakeholders in the enterprise sector should review their exposure to the vulnerabilities exploited in the observed campaign. Collaboration with threat intelligence providers can provide early warnings. The doubling of attack volume indicates a new normal in cyber conflict. Proactive measures are required to mitigate potential impacts. This development affects industries reliant on connected infrastructure.

The rise in autonomous capabilities changes the threat landscape for security teams. Traditional signature-based defenses may prove insufficient against AI-generated variations. Enterprises need to incorporate behavioral analytics into their toolkits. Training programs for incident responders should address AI-assisted tactics. Resource allocation toward threat hunting will likely increase as a result.

What expert reactions have been recorded regarding the use of DeepSeek?

Experts have pointed to the specific attributes of DeepSeek that make it attractive for malicious use. The low guardrails allow for queries that other models restrict. This characteristic has led to its adoption by the tracked actors.

DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrailsCharles Li, chief analyst at TeamT5

What developments are expected in the coming period?

Further integration of AI into cyber operations is anticipated as models improve. Other groups may adopt similar frameworks to enhance their capabilities. The observed success with autonomous campaigns could inspire additional experimentation. Security researchers will continue to monitor for new patterns. Enterprises should prepare for sustained high levels of activity.

The combination of open-source models and agent frameworks represents an accessible entry point for advanced tactics. This accessibility may lead to broader adoption among various threat actors. Ongoing analysis by firms like Palo Alto Networks Unit 42 will be essential. The situation highlights the dual-use nature of AI technologies. Vigilance remains key for all involved parties.

Future campaigns may incorporate additional AI models alongside DeepSeek. Refinements to agent frameworks could increase success rates beyond the current fourteen confirmed impacts. Enterprises must stay informed about emerging actor tactics. Collaboration across the security community will support collective defense efforts. The documented trends suggest continued evolution in offensive AI applications.

Frequently asked

How did the Chinese hackers use DeepSeek in their operations?

They integrated the model into the Hermes Agent framework to handle autonomous target enumeration, exploit sourcing, and attack execution after receiving a single instruction.

Why was DeepSeek preferred over other AI models?

It offered strong performance with minimal cyber guardrails, unlike alternatives such as Claude Code that imposed stricter restrictions on relevant queries.

What scale of activity resulted from the AI integration?

State-affiliated groups more than doubled their overall attack volume while one tracked actor reached over 460 systems with 14 confirmed successes in a single campaign.

Sources

  1. Bloomberg — Chinese state-affiliated cyber groups more than doubled the amount of attacks they carried out since they began delegating mundane tasks to AI and using it to develop advanced malicious software.
  2. Palo Alto Networks Unit 42 — Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact. The actor, operating under the aliases knaithe and KnYuan, leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator.
  3. The Straits Times — Chinese state-affiliated hackers have increased attacks by using DeepSeek and other open-source AI models to automate tasks and develop advanced malicious software, according to TeamT5. “DeepSeek is the AI of choice for…