Report Ads

Chinese Hackers Use DeepSeek and Open-Source AI Models to Scale Cyberattacks Worldwide

DeepSeek AI
From Data to Discovery—The DeepSeek Revolution. [TechGolly]

Key Points:

  • Cybersecurity researchers discovered that China-linked threat actors are actively integrating DeepSeek to automate and scale offensive cyber operations.
  • Attackers wired large language models into autonomous agent frameworks to scan internet registries and discover software vulnerabilities without human intervention.
  • The AI-augmented hacking campaigns targeted hundreds of thousands of internet-exposed servers and breached at least 85 foreign government accounts.
  • Threat actors are combining open-source Chinese models with Western tools to automate reconnaissance, test exploit code, and execute multi-step cyber intrusions.

The weaponization of artificial intelligence in cyber warfare has crossed from theoretical vulnerability research into active offensive deployment. Independent cybersecurity researchers and threat intelligence analysts reported that Chinese hacking groups and threat actors are integrating DeepSeek and other open-source artificial intelligence models into their daily attack pipelines. By combining high-speed neural networks with autonomous agent frameworks, malicious actors are expanding the speed, scale, and reach of cyber intrusions against foreign enterprises and government agencies.

The investigation revealed that threat actors wired DeepSeek models directly into autonomous agent frameworks, such as the open-source Hermes Agent system. By issuing high-level instructions through encrypted messaging platforms like Telegram, operators tasked the artificial intelligence model with functioning as an autonomous offensive operator. The agent scanned target networks, discovered software weaknesses, searched public code repositories for trending proof-of-concept exploits, and initiated attacks without requiring human intervention at every step.

The automated workflow proved remarkably efficient during target reconnaissance. In documented campaigns, the autonomous system surveyed ten distinct software product families and scanned global internet registries, identifying more than 647,000 exposed workflow automation servers worldwide. When initial intrusion attempts failed against restrictive corporate firewalls, the artificial intelligence agent autonomously pivoted, searching developer databases to prioritize seven high-value software vulnerabilities across enterprise infrastructure.

The impact of these AI-driven campaigns extended into high-stakes geopolitical targets. Threat intelligence reports confirmed that hacking groups utilizing open-source artificial intelligence agents successfully targeted foreign government infrastructure in Asia, compromising at least 85 government accounts. By automating credential theft and initial access probes, attackers lowered the operational costs of cyber espionage while overwhelming defensive security operations centers that handle an average of 2,336 weekly cyberattacks per organization.

While DeepSeek served as the primary operational engine, researchers observed attackers testing a diverse suite of competing foundation models. The threat actors configured alternative Chinese open-weight architectures—including Alibaba’s Qwen, Moonshot’s Kimi, and MiniMax—while simultaneously probing Western developer tools like Claude Code and OpenAI’s Codex. The hackers utilized Western tools through proxy networks to validate network connectivity and develop custom exploit directories, evaluating the broader artificial intelligence market to optimize their offensive toolkits.

To transform commercial and open-source models into functional cyber weapons, attackers relied on sophisticated jailbreaking techniques. Threat actors shared structured prompt-injection methods across underground developer forums to bypass anti-fraud protections, disable ethical safety filters, and extract functional exploit code. Because open-weight model architectures allow operators to download and run software on private servers, hackers can strip away central corporate safeguards entirely.

Security experts emphasize that the primary danger of artificial intelligence in cyber warfare is not that models never fail, but the unprecedented speed at which they adapt. When traditional human hackers encounter a patched vulnerability or a blocked port, manual reconnaissance can take days. An automated artificial intelligence agent, by contrast, can analyze defensive error logs, rewrite exploit scripts in seconds, and scan thousands of alternative targets simultaneously, handing offensive operators a massive asymmetric advantage.

In response to the growing wave of automated threats, cybersecurity providers and infrastructure operators are deploying advanced machine learning defenses to detect agentic intrusions. Enterprise defense teams are integrating behavioral analytics, automated threat-hunting algorithms, and strict network segmentation to identify anomalous scanning patterns before attackers gain a foothold. Security specialists advise organizations to patch internet-exposed software immediately and enforce multi-factor authentication across all external access gateways.

As artificial intelligence models become increasingly capable of independent reasoning and multi-step execution, the boundaries of global cybersecurity are permanently shifting. The integration of open-weight models into offensive hacking operations proves that advanced digital warfare tools are no longer reserved for elite intelligence agencies. Moving forward, defending critical infrastructure and enterprise networks will require deploying artificial intelligence defenses capable of matching the speed, autonomy, and scale of machine-driven cyberattacks.

Newsroom
Newsroom
Al Mahmud Al Mamun leads the TechGolly Newsroom team. He served as Editor-in-Chief of a world-leading professional research Magazine. Rasel Hossain is supporting as Managing Editor. Our team is intercorporate with technologists, researchers, and technology writers. We have substantial expertise in Information Technology (IT), Artificial Intelligence (AI), and Embedded Technology.