Researchers report surge in AI use by Chinese state-linked groups, leveraging open-weight models such as Kimi K3 and DeepSeek.
deepseek gemini google open-source
| Source: Techmeme | Original article
Researchers report Chinese state-linked hacking groups are increasingly using open-weight AI models like Kimi K3 and DeepSeek to power cyberattacks.
Researchers have mapped a surge in AI‑driven cyber operations among a broad swath of Chinese state‑linked hacking groups, noting a shift toward openly available large‑language models such as Kimi K3 and DeepSeek. The analysis, compiled from multiple threat‑intel feeds, shows these groups integrating generative AI into every stage of the attack lifecycle—from automated reconnaissance to payload development—thereby accelerating campaign speed and slashing operational costs.
The trend builds on earlier findings that Chinese actors have already weaponised commercial models. One report highlighted APT31 prompting Google’s Gemini to act as an “expert cybersecurity analyst,” using it to scan U.S. targets for exploitable flaws. Another campaign, GTG 1002, employed Claude to automate scanning, exploitation and data exfiltration, while Anthropic’s investigation revealed a separate group that jail‑broke Claude and let the model conduct 80‑90 % of the operation autonomously. Microsoft has warned that such AI‑enhanced tactics are now a staple of both Chinese and Russian threat actors, enabling rapid A/B testing, industry‑specific content tailoring and low‑cost targeting of critical infrastructure.
The proliferation of open‑weight models matters because they are freely downloadable and can be fine‑tuned without vendor oversight, lowering the barrier for sophisticated adversaries. Automated reasoning tools can generate phishing lures, craft exploit code and even adapt attacks in real time, widening the attack surface for governments, businesses and essential services.
Looking ahead, security teams will need to monitor the misuse of emerging open models and develop detection methods that recognise AI‑generated artefacts. Policymakers may consider tighter controls on the distribution of high‑capability models, while vendors are likely to roll out defensive extensions—such as watermarking or usage‑policy enforcement—to curb illicit exploitation. The next few months will reveal how quickly defenders can adapt to an adversary landscape increasingly powered by open‑source AI.
Sources
Back to AIPULSEN