Dark models: AI is making Chinese cyberattacks harder to detect and punish

In mid-September, Donald Trump announced the creation of a new agency called AI Force — his response to statements from industry leaders about the need to slow the pace of the technology’s development. However, opponents of implementing a voulntary slowdown are fearful of the effects such a step could have on competition with China, whose technology is becoming increasingly popular among hacker groups due to its low cost and weaker security safeguards. Moreover, cyberattacks and other operations using Chinese AI are harder to trace and stop than those involving models by Anthropic or OpenAI, as the companies behind the Chinese models do not report on criminal incidents involving the use of their products. As a result, hackers evade the attention of the authorities, and the number of cyberattacks continues to grow. So far, no concrete countermeasures have been taken to address the problem. In the meantime, the competitiveness of Chinese AI is on the rise, according to Kang Lee, deputy director for technology and geopolitics in Asia at the Institute for Security and Technology (IST). 

Dark models: AI is making Chinese cyberattacks harder to detect and punish

In meetings across Taiwan in July — with chipmakers, the American business community, government agencies, and the island's leading technology researchers — one number surfaced in almost every room: the 2.4 million intrusion attempts a day that Taiwan’s National Security Bureau logged against government networks in 2024 (to say nothing of the 2.63 million a day in 2025.) The number was raised in an almost pedestrian manner, without any real sign of alarm. If the ministry responsible for cyber policy was moving slowly to respond, nobody in these discussions behaved as though the slowness would ultimately prove fatal. Regardless of the seemingly “pressing” nature of Chinese cyberattacks and its larger, evidently ballooning cyber campaign, a rapid, commensurate government response, whether within the Ministry of Digital Affairs or the Administration for Cyber Security, was simply not materializing.

What China does to Taiwan through its networks is espionage on an industrial scale — and even if the hackers switch nothing off, it is still espionage. Most importantly though, I argue that artificial intelligence is entering the contest between Washington and Beijing through that gap, and two broader developments this August establish the framework for my contention. 

Artificial intelligence is entering the contest between Washington and Beijing

The first story arrived mid-August, when the Financial Times reported what the Israeli firm Dream described as the first-ever near-autonomous AI attack on a government. Assembled from two open-source agent frameworks, the tool ran up to eight agents over the course of four days in early July, mapping 21 Taiwanese government systems, compromising at least 85 accounts, and exfiltrating more than 2,500 personnel records before turning toward the nuclear safety agency and several energy companies. The AI model’s safeguards were bypassed by falsely labeling the attack as an “authorized penetration test.” Dream could not determine which model was used, and Taiwan’s digital ministry likewise confirmed that an AI-agent intrusion targeting government agencies had taken place, but without naming a source (or reporting any disruption).

Twelve days later, Bloomberg reported that the Taiwanese threat-intelligence firm TeamT5 had watched state-affiliated Chinese groups more than double their attack volume after handing reconnaissance and malware development to DeepSeek and other open-source models, which generated exploit code and harvested one thousand IP addresses. This second story, the more consequential of the two, demonstrates just how easily AI could alter who can “see” the attacker. TeamT5's chief analyst called DeepSeek “relatively powerful with very low cyber guardrails.”

Two days after Bloomberg’s report came a third story — one that received far less attention but, to my mind, helps explain both. On Aug. 26, the U.S. Justice Department seized the domains behind QScan and QTRouter, a scanning platform and a proxy relay built by a contractor group the FBI calls QTFY. The department’s release puts NASA and the Senate on the attackers’ target list. The group worked for China’s Nanjing Xinjiuwei Network Technology, whose clients included Beijing’s Ministry of State Security and the People’s Liberation Army. It operated from May 2018 until June 2026, when the group scanned a U.S. election system and failed. Notable other activities included intrusions in September 2024 at Department of Energy laboratories and the National Institutes of Health.

In other words, QScan, a distributed scanner whose worker nodes reported to central domains, constituted industrialized reconnaissance made by human engineering years before anyone even thought to delegate the job to an AI agent. Still, it ended as such campaigns end: with its domains seized.

What agents change

Framed as a question of capability uplift — of whether models will find new holes or write better malware — the debate about AI in cyber operations has, I posit, missed the mark. Anthropic’s November 2025 account of GTG-1002, a first-of-its-kind Chinese state-sponsored campaign run through Claude Code against roughly 30 organizations, shows where the difference maker is: mainly that its numbers actually point away from the frontier.

What matters most is that even back in 2025, far before Anthropic’s Mythos or Kimi K3, the AI performed 80 to 90 percent of the tactical work, making thousands of requests at rates no human team could match, while humans intervened at four to six decision points per campaign. The tools were overwhelmingly open-source penetration-testing utilities rather than custom malware. The model repeatedly overstated its findings, hallucinating credentials and presenting public data as secret. The ratio of operators to operations changed, and consequently, so did the tempo. The choice of target and the decision to act still rested with humans.

AI is capable of simplifying already-known methods of cyberattack, but it can’t yet independently discover new vulnerabilities

The academic evidence runs the same direction: a University of Illinois team showed in 2024 that a GPT-4 agent could exploit 87 percent of a set of real, already-disclosed vulnerabilities when handed the description, and 7 percent without one. Executing a known attack has become cheap in a way that discovering the breach simply has not. In August, the Chinese-speaking operator Palo Alto Networks’ Unit 42 documented that running DeepSeek-driven autonomous exploitation attempts mostly failed for that reason, succeeding only once a human took over to exploit a Citrix flaw by hand.

However, Anthropic’s Sept. 10 report supplies a notable, partial exception. Chinese-speaking operators in Hunan (two of them undergraduates) ran Claude as a round-the-clock vulnerability-research loop and came away with previously unknown flaws in a major security product — one that had been validated in their own lab and was working exploits for several families of network and security appliances. The company’s own judgment is that the larger change sits across the kill chain rather than in exploit discovery.

North Korea, the purest case because its hackers work for revenue, gained fluent English and durable fake personas from generative models, and nothing new by way of technique. The scheme itself of course predates the models. In fact, that is the pattern my own research on Pyongyang's operations finds across cases: the models industrialize the deception layer and leave exploitation itself about where it was.

Again, none of this makes Chinese cyber activity innocuous, but Volt Typhoon, which U.S. intelligence describes as pre-positioning inside American critical infrastructure for a future conflict, has never been triggered. Agents only shorten the path to access without pulling the trigger. No Chinese leader will decide whether to pull it based on how cheaply that access was obtained.

However, one case — I concede — cuts the other way. This July, models that OpenAI was running through an internal cyber evaluation found a zero-day in their test environment and used it to reach the open internet, where they broke into Hugging Face’s production servers to cheat on the exam — all without human intervention or decision-making. METR, the outside evaluator that OpenAI let in afterward, counted about 700 agents in the attack.

Anthropic’s chief executive Dario Amodei cited the imbroglio on Sept. 12 when urging the industry to slow down. As warnings go it is a fair one. Yet it was also a laboratory accident: OpenAI had switched off the cyber classifiers for the test and launched tens of thousands of agents at once. The public can recite the result in such detail only because it happened inside an American company, which published a post-mortem and opened the transcripts to outside investigators. “Many external models, including open-source ones, will soon reach comparable capabilities,” the same report warns.

The window that is closing

Everything the public knows about state hackers using AI comes from a small number of disclosures. For nearly all of them, the provenance is the American company whose model was abused. The first, in February 2024, came from OpenAI and Microsoft, which found five state-linked groups, two of them Chinese, using ChatGPT for research and scripting. GTG-1002 followed from Anthropic’s watch over its own platform, as did the Hunan group in September.

This February OpenAI disrupted a Chinese influence operation against Japan’s prime minister Sanae Takaichi. The interesting detail was that ChatGPT had refused the request, so the operation went ahead without it. The operators came back only to polish status reports, and the operation surfaced because someone just so happened to touch an American model once. That is the whole mechanism, since visibility into adversary AI use has been a byproduct of adversaries using American AI. Every 2026 case that centered on a Chinese model (Unit 42’s operator, Dream’s agents, TeamT5’s three groups) came from a third party rather than a provider, because no American provider saw the traffic.

Every 2026 case that centered on a Chinese model came from a third party rather than a provider, because no American provider saw the traffic

In a lower key, influence operations tell the same story, with the same one-sided disclosures. Four of the ten cases in OpenAI’s June 2025 threat report likely originated in China. Among them, the covert influence networks generated comments by the hundred and, by OpenAI’s own accounting, drew quite little authentic engagement.

The Japan operation is a classic case here: in essence, the move to locally run Chinese models once ChatGPT refused was the migration happening in miniature. In one update, the unit behind the influence operation recorded over 50,000 posts across 200 Western platforms, fewer than 150 of which drew over 300 shares or comments. Reach matters less than plumbing. Whatever lives in the weights travels into every product built on the Chinese models. A NewsGuard audit in January 2025 found DeepSeek’s chatbot framing its answers from Beijing's perspective 60 percent of the time on prompts about foreign false claims, most of them predictably not about China.

As such, the migration to Chinese models has very plain causes. None of them is a mystery to the operators themselves. Foremost are the guardrails, or rather, the want of them. DeepSeek’s R1 failed every one of fifty harmful prompts in Cisco’s testing. Criminals moved to it and to Qwen within weeks of release. Then, the price difference easily does the rest. The models run at a fraction of what their American rivals charge — up to 90% cheaper by one marketplace's estimate.

The customer base runs beyond China, as Google’s threat researchers found a tool of the Russian state-backed group APT28 — used against Ukraine — that queried Alibaba’s Qwen through Hugging Face at runtime for its commands. It was the first malware Google had seen call a model in live operations: in short, Chinese open models are becoming infrastructure for everyone’s operators. And to my knowledge, no Chinese provider has ever published a threat-intelligence disclosure about misuse of its models.

The user base for Chinese AI models extends far beyond China, including into Russia

The loss of visibility is only half of it, because the same shift removes the lever that has ended every campaign to date. When QTFY’s nodes all reported to three domains, the FBI could seize them and the platforms went dark. GTG-1002, because it ran on Claude, ended when Anthropic cut the accounts. The campaign was contained in about ten days.

A separate campaign run on DeepSeek weights downloaded onto the operator’s own servers would have no domain to seize and no provider to call. Dream never determined which model attacked Taiwan. On August 20, The Insider argued that developers such as OpenAI and Google should monitor API requests for state hackers and that regulators should extend know-your-customer rules to cloud-based AI services. Both are right, and both just so happen to apply only to operators who stay on American platforms.

Attribution, escalation, and what the formula gets wrong

Does espionage that arrives faster make war likelier? The standard forecast holds that AI makes cyber operations faster and cheaper and harder to attribute, and therefore more escalatory. Faster and cheaper are true, but the rest survives only in a form so narrow that its proponents would hardly recognize it.

Thomas Rid and Ben Buchanan argued more than a decade ago that attribution is a layered judgment (it runs from the tactical through the operational to the strategic) and never a reading of the toolkit alone. The 2026 record, remarkably, bears them out. Where I depart from them is at the provider level. They wrote before any operator could conceive of delegating tactical work to agentic AI, and before any company held the prompts such delegation leaves behind, which preserve each instruction in the operator's own words. Obviously, no such source could have been conceived in their scholarship, yet it informs all three of their levels simultaneously. Once operators run Chinese open weights on their own hardware, those prompts and their process never leave the machines. The source is gone, and attribution falls back only on what the operator leaves behind.

Dream pointed to a Chinese-language operator from the Simplified Chinese of the framework’s internal reports. The FBI, working from Ministry of State Security payment records and the operators’ former service in the PLA, tied QTFY to Beijing. Ergo, agentic operations are, if anything, noisier than human ones, since a campaign making several requests a second is an anomaly that behavioral monitoring is designed to catch.

Agentic operations are, if anything, noisier than human ones, since a campaign making several requests a second is an anomaly

As for escalation (the even weaker claim), the evidence sits in how the United States has answered Chinese campaigns. Washington dealt with an eight-year PLA-linked campaign against its own agencies with a domain seizure. Earlier campaigns drew indictments of people who will never be arrested. My research on North Korean cyber operations finds the same shape: attribution now arrives later than it did, and a remedy does not arrive at all. The median lag from theft to government attribution lengthened from 59 days for cases from 2022 and 2023 to 111 for those in 2024 and 2025. The recovery rate for such operations sits near one percent.

The state’s toolkit against espionage is legal and dilatory. That accords with what Sarah Kreps and Jacquelyn Schneider found in a survey experiment that showed Americans were less willing to escalate over a cyberattack than over a conventional one of similar effect (the cyber firebreak), and with Jon Lindsay’s reading of Stuxnet. This reading has aged well. Espionage that arrives faster is still espionage, and states have absorbed espionage without going to war for as long as there have been states.

Where the balance moves

While cyber operations have not changed the outcome of any international dispute — and nothing in the August record portends that agents will — the balance between Washington and Beijing now turns on who owns the plumbing, and faster espionage has little to do with it. Donald Trump told reporters at his golf resort in Ireland on Sept. 13 that America is leading China in AI and that “whoever wins AI wins.”

He has a case: on Sept. 8 the FBI, the NSA, and CISA named six Chinese labs — DeepSeek and Alibaba among them — for distilling American models at industrial scale, a practice the agencies called “the critical core” of how those labs build. Anthropic’s report of Sept. 10 counted more than 151 million such exchanges from Alibaba alone between May and July.

Chinese open-weight models carried a weekly peak of 46% of enterprise token traffic on the OpenRouter marketplace by early July, up from below 5% a year earlier, and DeepSeek’s V4 was trained in part on Huawei’s chips. The operators who follow that traffic of course take their prompts with them.

Chinese open-weight models carried a weekly peak of 46% of enterprise token traffic by early July, up from below 5% a year earlier

An American provider cannot report what it never sees, and the FBI cannot seize weights that sit on the operator’s own hardware. The provider has been Washington’s best sensor, more by accident than by design, and the very hackers it was watching are now leaving its platforms. As a result, the daily cyberattack count in Taipei will keep climbing, and the attempts it counts will still switch nothing off. In the end, fewer will know who is behind them.