Chinese State Hackers Doubled Their Attack Volume Using DeepSeek AI
Bloomberg reported on August 24 that Chinese state-affiliated hacking groups have more than doubled their attack volume since they began using DeepSeek and other open-source AI models. According to the report, the groups have assigned some routine and more advanced tasks to the AI models. The integration of these models is presented as the reason for the increase. The report does not name the specific groups. It also does not provide precise figures for the doubling, such as the baseline attack volume.
A Unit 42 report described a Chinese-speaking actor wiring DeepSeek into the Hermes Agent framework. The actor used the setup to enumerate targets and start attacks. This description indicates the model was used for target discovery and attack initiation. The Unit 42 report is cited in the Bloomberg article. No additional details about the actor's identity or affiliation were given. The actor is described only as Chinese-speaking.
The title of the article is "Chinese State Hackers Doubled Their Attack Volume Using DeepSeek AI". The use of open-source AI by state-linked actors is presented as a notable development in cybersecurity. The article does not include comment from DeepSeek or any other parties. It also does not discuss countermeasures or defensive responses. The implications for defenders are not addressed in the excerpt. The report is limited to the observed behaviour of the groups.