CYBERSECURITYTRACKER
TRACKING6,902 stories in this site build1,444 vulnerability news stories in this site build
Permanent story citation

Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3753

As cited

Copy frozen at (site build).

ai security

Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm

A Chinese actor used a Deepseek AI agent to target a security firm's infrastructure, attempting to compromise over 1,200 hosts for proxyjacking and to establish a foothold for additional attacks. Jesta researchers discovered and analyzed the compromised model during their investigation.

Why it matters: Security practitioners need to understand that AI models can be weaponized as attack vectors and that monitoring for suspicious AI agent behavior is now part of threat defense; organizations running Deepseek or similar models should audit their deployments for similar compromises.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ai security

Chinese Actor Weaponizes Deepseek AI Agent to Attack Security Firm

Analysts at Jesta captured and examined a malicious artificial intelligence (AI) model linked to a Chinese threat actor. The model was attempting to compromise over 1,200 hosts for proxyjacking and to launch further attacks. Investigators warned that the activity could enable additional intrusion campaigns.

Why it matters: Security operations teams overseeing exposed servers should watch for signs of proxyjacking and unusual AI generated traffic, since the threat actor’s model sought to affect more than 1,200 hosts for hijacking and subsequent attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary