Skip to main content

Chinese Hackers Double Cyberattacks Using AI Assistance

Taiwanese cybersecurity firm Team-T5 has discovered that hacker groups linked to the Chinese government have doubled their cyberattacks by leveraging AI tools like DeepSig. According to Team-T5, the Grimfancy and Taleboy hacker groups used AI to identify vulnerable websites, servers, and IP addresses to find entry points. The investigation revealed that these hackers employed DeepSig, ChatGPT, and Cloud Code, raising concerns about greater risks if even more advanced AI hackers emerge in the future. (September 25, Kathmandu)

Team-T5 reported that the hacker group known as ‘Grimfancy’ utilized DeepSig to identify system weaknesses and prepare code to infiltrate targets. Another group, ‘Taleboy,’ collected nearly one thousand IP addresses from the internet and gathered details about websites and domains belonging to a single company. This indicates that the hackers used AI to understand a company’s digital infrastructure—determining which websites belonged to the same entity, which servers were weak, and where it was possible to launch attacks.

The research also showed that hackers did not rely solely on DeepSig but used ChatGPT and Cloud Code as well. When targeting a Western think tank, hackers accessed Signal app–related files from an employee’s computer and used ChatGPT to develop programs to open those files. In another case, Cloud Code was used to automatically target 30 organizations and companies. The AI autonomously tested websites and systems, located vulnerabilities, and attempted to penetrate other systems.

This development poses a novel challenge for cybersecurity. Previously, hackers spent significant time probing individual systems, but now AI enables a single group to attack numerous websites, companies, and institutions in a short period. However, the AI itself is not attacking independently; hackers provide instructions and connect these tools to specific programs to execute the attacks. Researchers worry that as more powerful AI tools fall into hackers’ hands, preventing cyberattacks and tracking criminals will become increasingly difficult.