Skip to main content
  • Home
  • Tech
  • “Writing Malware and Finding Vulnerabilities”: Low-Cost, Easily Modified Chinese AI Lowers Barriers to Cyberattacks

“Writing Malware and Finding Vulnerabilities”: Low-Cost, Easily Modified Chinese AI Lowers Barriers to Cyberattacks

Picture

Member for

1 year 10 months
Real name
Matthew Reuter
Bio
[email protected]

Matthew Reuter is a senior economic correspondent at The Economy, where he covers global financial markets, emerging technologies, and cross-border trade dynamics. With over a decade of experience reporting from major financial hubs—including London, New York, and Hong Kong—Matthew has developed a reputation for breaking complex economic stories into sharp, accessible narratives. Before joining The Economy, he worked at a leading European financial daily, where his investigative reporting on post-crisis banking reforms earned him recognition from the European Press Association. A graduate of the London School of Economics, Matthew holds dual degrees in economics and international relations. He is particularly interested in how data science and AI are reshaping market analysis and policymaking, often blending quantitative insights into his articles. Outside journalism, Matthew frequently moderates panels at global finance summits and guest lectures on financial journalism at top universities.

Modified

Low costs and unrestricted modification broaden access to Chinese AI
Hackers increasingly deploy models for reconnaissance and malware development
Lower attack preparation costs intensify security threats to financial firms and government agencies

Chinese artificial intelligence (AI) is being exploited in intrusions targeting financial institutions and government agencies as it lowers the costs and technical barriers facing hackers. Traces of a Chinese attack tool were detected in personal data breaches in South Korea’s financial sector, while an overseas case revealed attempts to use DeepSeek to compromise more than 460 servers worldwide. Because users can download models, run them independently and modify them for offensive purposes, developers face considerable difficulty controlling misuse after release. Hacking groups are capitalizing on this accessibility to reduce the manpower and time required for reconnaissance and malware development, while efforts to delegate decisions on subsequent attacks to AI are also taking shape.

China’s DeepSeek Used in Attempts to Breach More Than 460 Servers

According to information technology (IT) industry sources on October 6, a Chinese-language string, “ARTEX-自主渗透測試控制台” (ARTEX Autonomous Penetration Testing Console), was detected during personal data breaches on October 3 involving Shinhan Bank and other South Korean financial institutions, as the attacker attempted credential stuffing—automated login attempts using credential combinations—against systems including those used by loan solicitors. ARTEX is a China-based tool whose sophistication was demonstrated by its victory in a security challenge organized by the Baidu Security Response Center (BSRC). Credential stuffing is an attack in which previously leaked username and password combinations are automatically submitted to other services to gain account access. When the same login credentials are reused across multiple services, a breach at one can lead to account takeovers elsewhere.

Similar cases involving the misuse of open models have emerged in recent cyberattacks in the United States, Europe and Taiwan. In a report published in July this year, global cybersecurity company Palo Alto Networks said it had uncovered a case in which a Chinese threat actor combined DeepSeek, a Chinese open AI model, with an autonomous agent tool to attempt intrusions into more than 460 servers worldwide. The attacker initially sought to use OpenAI and Anthropic models but switched to DeepSeek, whose safety restrictions were comparatively lax, after encountering security guardrails. Acting on the attacker’s instructions, the DeepSeek-powered AI agent mapped attack paths, identified security vulnerabilities and automated intrusion attempts at scale.

European Government Agencies and Middle Eastern Financial Institutions Also Targeted by AI-Enabled Attacks

Incidents involving hackers using Chinese AI to attack financial institutions have also occurred in Europe and the Middle East. In Europe, investigators identified an attempt to steal government information by connecting Alibaba’s Qwen to malware. The Computer Emergency Response Team of Ukraine (CERT-UA) said it discovered LAMEHUG, malware that uses an AI model, in phishing emails targeting government officials in July last year. Impersonating ministry officials, the attacker sent compressed archives containing malicious files designed to connect to Qwen’s code-generation model when executed. Qwen converted instructions embedded in the malware into computer commands, which were then executed on the victim’s device.

In the Middle East, evidence of AI use in attacks targeting financial institutions has continued to emerge. According to technology publication Rest of World, the United Arab Emirates (UAE) Cybersecurity Council detected and blocked an attack in July that combined phishing, exploitation of software vulnerabilities and malware distribution against the financial sector. The council said the attackers used AI to refine their techniques, adding that financial services continued without disruption. An earlier attack in February sought to infiltrate government platforms and deploy ransomware, with authorities also identifying AI use in the development of the attack tools. Coordinated attacks targeting the aviation, energy and education sectors were subsequently identified in August, prompting the national response team to trace intrusion routes and contain their spread.

Chinese AI Models That Run on Personal Computers Lower Barriers to Hacking

The spread of AI-enabled hacking is closely tied to the accessibility of open-weight models released by Chinese companies. Users can download the weights of trained models and run them independently, while “distillation”—training smaller models on the responses and reasoning processes of larger ones—has reduced the computing resources required to operate them. DeepSeek previously released six distilled models ranging from 1.5 billion to 70 billion parameters, using data generated by its R1 reasoning model. Smaller versions have also been distributed through tools that run on personal computers, allowing users to select models suited to their hardware. Individuals can therefore establish their own large language model (LLM) runtime environments without bearing the cost of developing or training a model from scratch.

A distribution model that allows users to possess and modify models directly also constrains efforts to control misuse. The UK AI Security Institute (AISI) has warned that safeguards applied to open-weight models can be removed quickly and at little cost. Once users download a model and run it on their own hardware, developers have limited ability to continuously monitor inputs and outputs or revoke access. Malicious users who modify and redistribute models could also circulate derivative versions with harmful capabilities. AISI explicitly identified limits to post-release risk management, noting the difficulty of recalling weights that have already been made public.

Table 1. Factors Driving the Misuse of Chinese Open-Weight AI in Hacking and Notable Cases

CategoryKey Details
Broader accessibilityPublicly released weights can be downloaded and run independently. Smaller distilled models reduce computing requirements, enabling individuals to establish their own LLM environments.
Limits to misuse controlsSafeguards can be removed, and models modified and redistributed. Local execution makes it difficult for developers to monitor use or revoke access, while publicly released weights are difficult to recall.
Lower attack costsReduced manpower and time required for target reconnaissance and malware development. TeamT5 research found that attack volumes more than doubled after Chinese government-linked hacking groups adopted AI.
Use by North Korean groupsMIDNIGHT NEPTUNE used DeepSeek and other models to develop remote-control malware. AI also supported the creation of persistence and detection-evasion capabilities, impersonation messages and code for lateral movement within corporate networks.
Sources: DeepSeek, UK AI Security Institute (AISI), Bloomberg, TeamT5, Google Threat Intelligence Group (GTIG)

Hackers Use Low-Cost AI to Scale Up Attacks

Low operating costs are another factor encouraging the misuse of Chinese open-weight models in hacking. According to research by Taiwanese cybersecurity company TeamT5 cited by Bloomberg, attack volumes more than doubled after Chinese government-linked hacking groups began using AI for repetitive tasks and malicious software development. Researchers identified low running costs, broad utility and the flexibility to modify models for offensive purposes as reasons for DeepSeek’s appeal. In scripts and activity logs collected over recent months, TeamT5 found evidence of AI use in target reconnaissance and exploit-code development. Its assessment was that reducing the manpower and time required to prepare attacks had increased the volume of work the same groups could perform.

North Korea-linked hacking groups have also been found using Chinese AI to develop malware. In a report published last month, Google Threat Intelligence Group (GTIG) said MIDNIGHT NEPTUNE, a group seeking to steal cryptoassets, had used DeepSeek’s coding model and other tools to develop remote-control malware. AI helped implement capabilities to maintain access to infected devices and evade security detection. The group also used AI to create fictitious personas and draft messages posing as technical support to deceive employees of cryptocurrency companies. LLMs were additionally used to write code for lateral movement to other systems within compromised corporate networks.

AI Now Decides Malware’s Next Moves

The misuse of Chinese AI is extending beyond writing attack code to attempts to delegate decisions about malware behavior. On September 22, Cisco’s security research organization Talos disclosed CLOSEDQUORUM, malware designed to select its next task based on responses from as many as four AI models, including DeepSeek and Qwen. It sends device information to each model and aggregates their responses to choose actions such as credential theft or establishing persistent access. When an equal number of responses recommend different actions, the malware is programmed to prioritize DeepSeek’s judgment, with Qwen taking precedence if DeepSeek does not respond. The design allows subsequent tasks to proceed on the basis of AI decisions without requiring fresh instructions from the attacker each time.

CLOSEDQUORUM also appears to have been developed with individually customized distribution in mind. In development files, Talos found a function that embeds each user’s AI service credentials and data-receiving endpoints into the malware. On that basis, researchers inferred a division of roles in which the developer supplies customized executables and users distribute them to target devices. After deployment, the malware is designed to send the tasks selected by AI and the reasoning behind those choices to the user’s Discord channel. Stolen credentials and cryptocurrency wallet data are also configured to be sent to the same channel, allowing users to monitor attack progress while receiving the collected information.

Scanning 170,000 Web Addresses with AI to Identify Intrusion Targets

Evidence has also emerged of AI-integrated attack tools being used to scout large numbers of targets. In a case involving the Chinese-speaking hacking group UAT-10147 disclosed by Talos in August, investigators discovered a target list containing approximately 170,000 web addresses on a command-and-control server. The group divided the list into batches of 10,000 to reduce scanning time and used the AI-powered penetration-testing tool PentestGPT for server reconnaissance and vulnerability validation. Among the targets identified, web servers in the government, education, media and technology sectors across multiple countries were found to have been exposed to attacks exploiting publicly disclosed vulnerabilities. Website intrusion logs and records of information collected from victim devices obtained by Talos provide evidence that AI tools were deployed in actual attacks.

AI was also used to diagnose errors during intrusions and review subsequent tasks. Materials obtained by Talos included documentation describing attack procedures, alongside automated programs for checking file-write permissions, installing malware and establishing remote access. The programs included functions to verify task results and retry failed downloads using alternative methods, while AI also supported the process of validating whether attack code worked correctly in the target environment. Its role therefore extended from writing code to reviewing execution results and correcting errors. Talos assessed that this automation reduced the expertise and operational burden required for complex intrusions.

Picture

Member for

1 year 10 months
Real name
Matthew Reuter
Bio
[email protected]

Matthew Reuter is a senior economic correspondent at The Economy, where he covers global financial markets, emerging technologies, and cross-border trade dynamics. With over a decade of experience reporting from major financial hubs—including London, New York, and Hong Kong—Matthew has developed a reputation for breaking complex economic stories into sharp, accessible narratives. Before joining The Economy, he worked at a leading European financial daily, where his investigative reporting on post-crisis banking reforms earned him recognition from the European Press Association. A graduate of the London School of Economics, Matthew holds dual degrees in economics and international relations. He is particularly interested in how data science and AI are reshaping market analysis and policymaking, often blending quantitative insights into his articles. Outside journalism, Matthew frequently moderates panels at global finance summits and guest lectures on financial journalism at top universities.