Case · DiggingBeagle record

TeamT5 says Chinese state-linked hackers scaled attacks with DeepSeek and other models

TeamT5 reported that Chinese state-affiliated cyber groups increased attack volume after integrating DeepSeek and other open-source models into operational workflows. Researchers described AI use for mundane task delegation and malware development, while also noting that the exact model could not always be identified.

Evidence boundary

An explicit boundary statement has not yet been recorded. The evidence ledger defines what can be supported.

Assessment profile

How to read this
Setting
allegation
Exploitation
not established
Impact
Unassessed
Evidence
U - unassessed
Remediation
unknown
AI role
WITH AI
Basis and provenance

The report attributes an attack-volume increase and model preference to TeamT5 but does not establish causation or per-campaign model identity. Generic locators and missing campaign-level proof leave evidence and impact grading unresolved. Assessment is a desk review of the retained canonical Claims and cited Source metadata at their recorded cutoff, not a new external verification. Impact remains ungraded. Stored evidence uses source-level locators; passage-level corroboration remains required.

Assessed Sep 24, 2026 using diggingbeagle.assessment/1.

These dimensions are not combined into a threat score. An evidence grade does not establish exploitation or likelihood.

30-second account

Mechanism and trust boundary

Typed chronology

No typed chronology has been recorded. Dates are not inferred from the title or the Release build.

Claims & evidence

5 independently addressable Claims. Expand a Claim to inspect support, contradiction and scope.

CLM-USESResearchers described AI being used both for routine operational work and for developing more advanced malicious software.supported

Basis: reported finding

Permanent Claim anchor
CLM-MODELDeepSeek is reported as popular among the groups, but TeamT5 said it cannot identify the exact model used in every intrusion.contested

Basis: reported finding

Permanent Claim anchor
CLM-DOUBLEBloomberg reporting attributes to TeamT5 the claim that attack volume more than doubled after AI adoption.supported

Basis: reported finding

Permanent Claim anchor
CLM-SCALE2TeamT5 told Bloomberg Law that state-affiliated groups more than doubled attack volume after integrating AI into operations.supported

Basis: reported finding

Permanent Claim anchor
CLM-ATTR-LIMITTeamT5 said the specific model could not always be determined, although DeepSeek models were popular among China-based attackers.supported

Basis: reported finding

Permanent Claim anchor

Implications within the documented scope

Controls and mitigations

No controls or verified fix are recorded.

Unknowns and contradictions

  • The reporting does not establish that every measured attack increase was caused by AI rather than concurrent operational changes.
  • Per-campaign model attribution is incomplete.

DeepSeek is reported as popular among the groups, but TeamT5 said it cannot identify the exact model used in every intrusion. has a contested assessment or contradictory evidence.

Sources and citation

Material revision history

  1. Sep 25, 2026 · Published version · first publication · revision 39

Cite this record

DiggingBeagle. “TeamT5 says Chinese state-linked hackers scaled attacks with DeepSeek and other models.” Published by DiggingBeagle Sep 25, 2026. https://diggingbeagle.com/cases/teamt5-says-chinese-state-linked-hackers-scaled-attacks-with-deepseek-and-other-/

Citation guidance

Independent research

The source stays with the story.

Claims, evidence and corrections remain inspectable. About the project · Our methodology