Modelwire
Subscribe

Chinese state hackers double attacks using DeepSeek and Claude for exploit code

Illustration accompanying: Taiwanese cybersecurity firm warns that AI tools have more than doubled Chinese state-backed cyberattacks

Chinese state-backed threat actors have weaponized open-source and commercial LLMs to automate exploit development and network reconnaissance, resulting in a documented doubling of attack volume. The shift signals a critical inflection point where commodity AI models now meaningfully amplify the operational capacity of well-resourced adversaries. This development underscores an emerging asymmetry in cybersecurity: defensive capabilities lag behind the speed at which attackers can scale reconnaissance and payload generation using publicly available models, raising urgent questions about responsible model deployment and the security posture of organizations facing state-level threats.

Modelwire context

Explainer

The detail worth sitting with is that open-source models, not just commercial ones, are central to this acceleration. Because open-source weights can be fine-tuned and run locally without usage logging or rate limits, defenders have no visibility into how those models are being adapted, which is a materially different threat surface than misuse of API-gated products.

This is largely disconnected from recent activity in our archive, as Modelwire has not yet covered the intersection of AI model deployment and offensive cyber operations. The story belongs to a broader conversation happening across national security and infosec communities about dual-use risk, a conversation that has so far centered on biosecurity and disinformation rather than network intrusion. TeamT5's framing is notable because it moves the discussion from theoretical misuse scenarios to documented operational outcomes, which is a harder claim to dismiss.

Watch whether any of the named commercial providers, particularly Anthropic or the teams behind DeepSeek, respond with updated acceptable-use enforcement or model-level mitigations within the next two quarters. If they do not, that silence will itself become a data point about how seriously the industry treats state-actor misuse as a product problem rather than a policy problem.

This analysis is generated by Modelwire’s editorial layer from our archive and the summary above. It is not a substitute for the original reporting. How we write it.

MentionsTeamT5 · DeepSeek · ChatGPT · Claude · Chinese state-backed threat actors

MW

Modelwire Editorial

This synthesis and analysis was prepared by the Modelwire editorial team. We use advanced language models to read, ground, and connect the day’s most significant AI developments, providing original strategic context that helps practitioners and leaders stay ahead of the frontier.

Modelwire summarizes, we don’t republish. The Decoder originally reported this story as Taiwanese cybersecurity firm warns that AI tools have more than doubled Chinese state-backed cyberattacks”. The full content lives on the-decoder.com. If you’re a publisher and want a different summarization policy for your work, see our takedown page.

Chinese state hackers double attacks using DeepSeek and Claude for exploit code · Modelwire