8 October 2026

Dark models: AI is making Chinese cyberattacks harder to detect and punish

The Insider | Kang Lee

Chinese state-sponsored cyber groups are leveraging open-source artificial intelligence models like DeepSeek to dramatically scale up reconnaissance and exploit execution against Taiwanese government networks. This technological shift allows threat actors to bypass traditional detection mechanisms while significantly reducing the human resources required to sustain high-volume intrusion attempts.

Historically, tracking these operations relied on visibility into Western platforms like OpenAI's ChatGPT or Anthropic's Claude, which actively report malicious activity. However, the transition to domestic, open-source Chinese models closes this visibility window, leaving defenders reliant on third-party threat intelligence. In July 2026, a near-autonomous multi-agent AI framework compromised 85 Taiwanese government accounts and exfiltrated 2,500 personnel records. AI cannot yet independently discover novel vulnerabilities. Instead, it industrializes the deception and exploitation layers of existing flaws. This automation alters the tempo of cyber warfare by shifting the operator-to-operation ratio, enabling continuous, low-cost targeting of critical infrastructure.

Comment

The migration of Chinese state-sponsored threat actors from Western hosted platforms to domestic open-source models like DeepSeek fundamentally degrades allied cyber intelligence telemetry. When campaigns like GTG-1002 utilised Claude Code, developers at Anthropic could directly observe and disrupt the malicious activity at the model layer. By contrast, the deployment of DeepSeek-driven autonomous agents leaves no footprint on Western servers, blinding agencies like the FBI to early-stage reconnaissance. This shift effectively neutralises the proactive disruption model pioneered by OpenAI and Microsoft in early 2024.

Consequently, this loss of upstream visibility shifts the defensive burden entirely to decentralised endpoint detection across the Department of Energy laboratories targeted by QTFY. This transition places an immediate, unsustainable burden on municipal infrastructure targets, which lack the sophisticated threat-hunting capabilities of the Cybersecurity and Infrastructure Security Agency. Without centralised telemetry from platforms like ChatGPT, identifying automated reconnaissance campaigns against U.S. election systems becomes nearly impossible.

Strategic Question for Discussion
If Chinese threat actors completely transition from Western APIs to self-hosted DeepSeek models, what happens to the viability of public-private threat intelligence sharing as a primary pillar of allied cyber defense?
My assessment is that a complete transition to self-hosted DeepSeek models will render traditional public-private sharing models obsolete, as tech giants lose the direct platform telemetry that previously fueled joint disclosures. Allied cyber defense will likely fragment, forcing agencies to rely on lagging indicators like network-level anomalies rather than proactive, model-level interventions. This shift will ultimately elevate the role of specialized threat-intelligence firms over cloud providers in the early detection of state-sponsored campaigns.
Share your assessment in the comments below.
💬
Ask Strategic Study India ×