Threat Intelligence

Chinese Threat Actor Weaponises DeepSeek AI Agent in Attack on Security Firm

Dark Reading · 4 Aug 2026
Key Takeaway Ensure your internet-facing systems are patched and monitored, as attackers are increasingly using AI tools to automate and scale compromise attempts.

Security researchers at Jesta have identified and analysed a case in which a Chinese threat actor weaponised an AI agent built on the DeepSeek model to launch attacks against a security firm. The AI-powered tool was reportedly used in an attempt to compromise more than 1,200 hosts, with the ultimate goal of enabling proxyjacking—a technique where compromised systems are used to route traffic through unauthorised proxy networks, often for profit or to mask further malicious activity.

The incident highlights a growing trend where attackers are experimenting with AI models not just for social engineering or content generation, but as active tools within their attack infrastructure. By automating parts of the compromise and propagation process, threat actors may be able to scale attacks more efficiently and adapt to defensive measures in real time.

While details on the specific vulnerabilities exploited remain limited, the case serves as an early signal that AI-driven attack tooling is moving from theoretical concern to real-world deployment. Businesses relying on internet-facing infrastructure should treat this as a reminder that the threat landscape is evolving alongside AI adoption on both the defensive and offensive sides.

AI security DeepSeek proxyjacking threat intelligence China-linked threats
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.