Chinese Threat Actor Weaponises DeepSeek AI Agent in Attack on Security Firm
Security researchers at Jesta have identified and analysed a case in which a Chinese threat actor weaponised an AI agent built on the DeepSeek model to launch attacks against a security firm. The AI-powered tool was reportedly used in an attempt to compromise more than 1,200 hosts, with the ultimate goal of enabling proxyjacking—a technique where compromised systems are used to route traffic through unauthorised proxy networks, often for profit or to mask further malicious activity.
The incident highlights a growing trend where attackers are experimenting with AI models not just for social engineering or content generation, but as active tools within their attack infrastructure. By automating parts of the compromise and propagation process, threat actors may be able to scale attacks more efficiently and adapt to defensive measures in real time.
While details on the specific vulnerabilities exploited remain limited, the case serves as an early signal that AI-driven attack tooling is moving from theoretical concern to real-world deployment. Businesses relying on internet-facing infrastructure should treat this as a reminder that the threat landscape is evolving alongside AI adoption on both the defensive and offensive sides.