
Image to help understand the article
AI’s cyber risk is shifting from brilliance to volume
A new assessment from TeamT5, a Taiwan-based cyber threat research group, points to a development that should get the attention of Washington, Silicon Valley and any American company with operations in Asia: Chinese hacking groups tied to the state are reportedly using the Chinese artificial intelligence model DeepSeek widely in attacks on overseas targets, and the pace of those attacks has more than doubled after AI was folded into their workflow.
That finding matters not because DeepSeek is necessarily the most powerful model available in China. According to TeamT5’s report on 2025 Asia-Pacific advanced persistent threat trends, the bigger story is that attackers do not always need the smartest AI system. In practice, they may prefer one that is cheap to run, easy to scale and less constrained by guardrails designed to block abuse.
For American readers, the easiest comparison is not the race among the best consumer chatbots. It is the difference between a luxury sports car and a fleet of inexpensive delivery vans. In cyber operations, a tool does not have to be the fastest thing on the road if it can move far more material, more often, at lower cost. TeamT5’s central warning is that AI is acting less like a magic new hacking trick and more like an attack amplifier, speeding up the repetitive, labor-intensive parts of cyber intrusions so experienced operators can focus on the harder work.
That distinction is important. Public debates about AI and security often revolve around the fear that a model will suddenly invent a completely unprecedented cyberweapon. What TeamT5 describes is subtler and, in some ways, more immediate. Instead of replacing hackers, AI is boosting their productivity. It can automate rote tasks, help generate code, assist with malware development and accelerate the cycle of testing, revising and launching more attacks. Even if the quality of each individual output is uneven, a skilled human operator can filter and refine the results.
In other words, the threat may not begin with more sophisticated attacks. It may begin with more attacks, period. For defenders, that alone can be enough to change the equation. Security teams already struggle with alert fatigue, staffing shortages and the need to distinguish harmless noise from a real breach attempt. If AI helps hostile groups flood the zone, the burden on defenders rises long before any single attack becomes truly novel.
Why a weaker model can still be the better weapon
One of the most revealing parts of TeamT5’s analysis is its suggestion that Chinese hacking groups are drawn to DeepSeek not despite its limitations, but because of features that are useful in malicious operations. The report says stronger Chinese models exist, including Moonshot AI’s Kimi K3, yet attackers appear to value DeepSeek’s relatively weak cyber safety barriers and low operating costs.
That is a lesson the broader AI industry, including American companies, may need to absorb quickly. In mainstream product competition, developers tend to emphasize reasoning ability, benchmark scores, speed and user experience. But in abuse scenarios, the ranking criteria change. A bad actor may care less about whether a model is the best in class and more about whether it can be cheaply prompted over and over, whether refusals are easy to bypass, and whether the system can be deployed in multiple environments without much friction.
That is especially true in the world of open-source or openly available AI systems. These models can deliver genuine benefits to researchers, startups and independent developers. They also lower barriers for people who want to automate harmful tasks. Once a model becomes easy to access and inexpensive to operate, the economics start to favor scale. A tool that produces merely adequate results thousands of times may be more dangerous than a premium model whose protections are stricter and whose operating costs limit mass use.
Americans have already seen versions of this logic elsewhere in the digital economy. Spam did not require masterful writing. Robocalls did not depend on eloquence. Disinformation campaigns on social media often succeeded through repetition and reach more than quality. TeamT5’s report suggests cyberattacks may be moving further in that direction as AI spreads: not every attempt has to be elite if enough attempts can be launched cheaply and continuously.
That also helps explain why guardrails matter as much as raw model capability. If an AI system is easy to coax into generating malicious guidance, code fragments or workflow support, a lower-performing model can still become highly practical in the hands of an experienced attacker. The danger emerges from the combination of human expertise, automation, low cost and weak safeguards. Looking only at model intelligence misses the real-world abuse case.
What the report does and does not show
It is worth being precise here, because cyber reporting can easily slide into alarmism. TeamT5’s reported finding is that attack frequency more than doubled after Chinese state-linked groups began using AI for repetitive work and more advanced malware development. That is significant. But it is not the same as proving that each attack became more successful, more destructive or more technically groundbreaking.
The report, as summarized, points to a structural shift rather than a cinematic leap. AI is helping experienced groups do more of what they already do. It is compressing timelines, expanding output and potentially allowing human operators to spend more time on the parts of an intrusion that require judgment. For defenders, that means counting only high-end breakthroughs may understate the risk. Volume itself can become a strategic advantage.
This is a familiar problem in cybersecurity. A company may be able to stop a highly sophisticated intrusion if it is rare and resource-intensive. It is much harder to maintain the same defense posture when the number of intrusion attempts, phishing lures, malware variants or reconnaissance tasks rises dramatically. More attempts create more chances for a mistake. They also consume analysts’ time, drive up costs and force organizations to triage under pressure.
TeamT5’s findings also underscore an analytical trap in AI safety debates. Policymakers, investors and the public often focus on frontier models, the most advanced systems produced by top labs. But a threat ecosystem does not need the best model to become more dangerous. Sometimes what changes first is not the quality of the attack but the scale at which the attack pipeline can run. Cheap, accessible models with weaker misuse protections may be enough to alter the threat landscape in measurable ways.
That nuance matters because it suggests the policy response cannot revolve only around a small handful of top-tier companies. Mid-tier models, open deployments, API pricing, refusal systems and monitoring practices all become part of the security conversation. The next phase of AI risk may be shaped as much by what is widely available as by what is most advanced.
Why this matters in the United States
For the United States, this development lands at the intersection of several national concerns: cyber defense, strategic competition with China, the security of US companies operating across Asia, and the increasingly close technology relationship between Washington and Seoul. American businesses, universities, defense contractors and infrastructure operators have long been targets of Chinese cyber espionage. If AI is now helping hostile groups increase attack tempo, the pressure on US networks may intensify even if no single tactic looks revolutionary on its own.
There is also a direct commercial angle. American cloud providers, software makers, chip companies and cybersecurity firms are all deeply invested in the AI boom. Many have framed safety as a differentiator, arguing that robust guardrails and responsible deployment can set trusted products apart. TeamT5’s findings suggest that argument is not just about ethics or public relations. It may become a hard market question: Which AI systems can be used at scale without becoming cheap labor for cybercriminals and state-linked hackers?
US companies will likely see parallels to familiar debates at home. American tech firms have wrestled with how much openness is too much, how to police dual-use tools, and how to balance innovation against the risk of abuse. The same tension has played out in software encryption, social media moderation and generative AI image tools. What is different here is the geopolitical context. A model that is permissive, inexpensive and easy to manipulate is not only a product risk. It can become part of a foreign cyber capability stack.
For American audiences, another useful comparison is the evolution of ransomware and business email compromise. Those threats did not depend on a single dazzling innovation. They became huge because attackers industrialized them. Playbooks were standardized. Services were outsourced. Targeting became scalable. AI may now be helping state-linked espionage groups borrow that same logic of industrial efficiency, even if their goals differ from purely criminal gangs.
The US-Korea relationship adds another layer. South Korea is one of America’s closest allies in Asia, a major technology power and a critical node in global semiconductor and electronics supply chains. Threat activity affecting the broader Asia-Pacific region rarely stays local in its consequences. If cyber operations tied to Chinese actors accelerate across the region, American firms and institutions connected to Korean partners, vendors or joint ventures may feel the effects indirectly as well as directly.
There is a political dimension, too. In Washington, policymakers are already debating export controls, digital sovereignty, AI governance and cyber resilience. Evidence that lower-cost Chinese AI tools are being used as attack multipliers could reinforce arguments for tighter scrutiny of foreign AI ecosystems, more aggressive threat-sharing with allies, and stronger baseline cybersecurity rules for critical sectors. It could also sharpen pressure on US companies to show that their own models are harder to abuse.
South Korea, Taiwan and the wider Asia technology front line
Although the reported findings come from a Taiwan-based research organization and focus on Chinese groups targeting overseas victims, the broader backdrop is a region where cyber conflict, economic competition and national security increasingly overlap. Taiwan sits on the front line of tensions with Beijing and has long been a high-priority target for cyber operations. South Korea, for its part, faces constant pressure from North Korean cyber actors while also navigating a complex economic relationship with China and a military alliance with the United States.
For American readers, it helps to think of East Asia not simply as a distant theater but as the nerve center of industries the United States depends on every day. Semiconductors, smartphones, displays, batteries, cloud infrastructure and advanced manufacturing all run through networks in South Korea, Taiwan and neighboring economies. If the region sees an increase in AI-assisted cyber activity, the consequences can ripple into American supply chains, consumer electronics markets and corporate risk planning.
That is one reason this story deserves attention beyond the cybersecurity niche. Korean technology companies are global household names. Taiwanese chipmakers sit near the heart of the modern computing economy. Cyber operations aimed at organizations in the region can affect everything from intellectual property and procurement timelines to investor confidence and cross-border collaboration. The issue is not just whether a single target gets hacked. It is whether the operational environment becomes noisier, more expensive and harder to defend at scale.
The report also adds to a larger picture in which AI development is no longer separable from national security strategy. Countries want fast-moving AI sectors for economic reasons, military reasons and prestige. But as models spread, the downside of weak safety controls also spreads. A country or company that wins market share with a cheap, flexible model may also be exporting cyber risk if misuse protections lag behind adoption.
That creates difficult policy trade-offs for democracies that support open research and competitive innovation. American and allied governments want vibrant AI ecosystems. They also want to prevent those ecosystems from becoming force multipliers for hostile actors. The challenge will be building rules and norms that preserve useful openness without assuming all users are acting in good faith.
The real test for AI safety is operational, not theoretical
One of the clearest takeaways from TeamT5’s findings is that AI safety cannot be treated as a side feature, a box to check after a model ships. If the report is correct, then weak safeguards, low cost and broad accessibility can combine to make even a less capable model attractive for malicious use. That means the relevant question is not just whether a system can refuse an obviously dangerous prompt in a lab setting. It is whether protections hold up under repeated, adaptive, real-world abuse.
That is an operational challenge as much as a technical one. Developers may need better monitoring for suspicious patterns, stronger rate limits, more robust refusal behavior for cyber abuse prompts and clearer incident-response mechanisms when misuse is detected. Open-source communities may need to think harder about downstream deployment norms. Enterprise customers may need more visibility into how models are being integrated into security-sensitive workflows. Governments, meanwhile, may need to move past broad rhetoric about AI leadership and confront the mundane details of procurement standards, audit requirements and cross-border information sharing.
For defenders, the lesson is equally practical. Security teams cannot focus only on whether a piece of malware was AI-generated or whether a phishing email sounds machine-written. The deeper issue is process acceleration. If attackers are dividing labor between humans and AI, defenders need to watch for changes in tempo, repetition and scaling behavior. A surge in low- to mid-level malicious activity may signal a more consequential shift underneath.
What to watch next is not merely whether another report names DeepSeek or a rival model. It is whether more threat intelligence firms begin documenting the same pattern across different actor groups and regions. If they do, the policy conversation will likely move from abstract worries about AI-enabled hacking to concrete debates about liability, model distribution and the minimum safety expectations for systems that can be repurposed for cyber operations.
The broader message is uncomfortable but clear. In the AI era, danger does not arrive only when a dazzling new model breaks records. It can also arrive when an ordinary-enough model becomes cheap, easy to manipulate and useful at industrial scale. In cybersecurity, as in so many other areas of modern technology, the power to do something repeatedly and cheaply can matter just as much as the power to do it brilliantly once.
0 Comments