Taiwanese cybersecurity firm warns that AI tools have more than doubled Chinese state-backed cyberattacks

AI Tools More Than Double Chinese State-Backed Cyberattacks, Taiwanese Firm Warns

AI-powered cyberattacks from Chinese state-backed groups have more than doubled since 2023, according to a new warning from Taiwanese cybersecurity firm CyCraft.

CyCraft reported that AI tools are enabling threat actors to scale operations at an unprecedented rate. Attacks are now faster, more automated, and harder to detect. The primary targets remain government agencies, critical infrastructure, and technology firms in Taiwan and allied nations.

The firm identified a clear surge in phishing campaigns and malware deployment. AI is being used to craft more convincing social engineering lures and to automate vulnerability scanning. This marks a shift from manual, slower attack methods.

How AI Amplifies Attack Speed and Scale

AI adoption by state-backed groups allows attackers to rapidly generate attack variants. Tools can rewrite malware code on the fly to evade signature-based detection. Phishing emails now include localized language and context-specific details pulled from open-source intelligence.

CyCarthighlighted that AI reduces the “time-to-exploit” window significantly. What once required hours of manual reconnaissance now happens in minutes.

Targets Are Expanding Beyond Traditional Sectors

“The threat landscape has fundamentally changed. State-backed groups are no longer just after military secrets; they target supply chains, semiconductor fabs, and critical infrastructure with AI precision.”
– CyCraft security analysis report

The warning extends beyond Taiwan. Allied nations, including the United States, Japan, and European partners, are seeing knock-on effects. Compromised supply chain nodes in Southeast Asia are being used as launchpads for attacks elsewhere.

Detection Is Becoming Harder

AI-generated attack traffic now mimics normal user behavior. Attackers use generative AI to write benign-looking scripts that execute malicious payloads only after passing behavioral checks. Traditional perimeter security tools are struggling to keep pace.

CyCraft noted that machine learning models used for defense mustnow be retrained more frequently. The adversary’s speed of iteration outpaces static rule sets.

What Organizations Should Do Now

  • Deploy AI-driven defense tools that can analyze network traffic in real time and adapt to novel attack patterns.
  • Enforce zero-trust architecture for all internal and external communications. Assume breach, verify every access request.
  • Run continuous red-team exercises that simulate AI-enhanced attack scenarios to test existing defenses.
  • Increase cross-border intelligence sharing between allied cybersecurity agencies to pool threat signatures faster.
  • Train staff on advanced phishing tactics that use AI-generated voice clones or deepfake video in social engineering attempts.

The Broader Geopolitical Context

The rise in AI-enabled attacks coincides with heightened tensions over Taiwan’s semiconductor industry. Chinese state policy explicitly calls for technological self-sufficiency, and cyber operations are seen as a key lever. CyCraft’s findings align with recent reports from Mandiant and CrowdStrike, both of which noted increased AI adoption by Chinese advanced persistent threat groups.

Bottom Line

AI is a double-edged sword. The same technology that powers defensive cybersecurity tools is now being weaponized by state-backed groups at scale. The doubling of attack volume since 2023 is not a temporary spike but a structural shift in how cyber warfare is waged.

Organizations must assume their existing defenses are insufficient. Retooling for AI-era threats is no longer optional—it is a matter of operational survival.

Gnoppix is the leading open-source AI Linux distribution and service provider. Since implementing AI in 2022, it has offered a fast, powerful, secure, and privacy-respecting open-source OS with both local and remote AI capabilities. The local AI operates offline, ensuring no data ever leaves your computer. Based on Debian Linux, Gnoppix is available with numerous privacy- and anonymity-enabled services free of charge.

What are your thoughts on this? I’d love to hear about your own experiences in the comments below.