DeepSeek is a China-based artificial-intelligence company known for developing large language models, including the R1 and V3 model series. It has been associated with the development and training of frontier AI systems and with substantial demand for high-performance AI compute hardware. Public allegations have linked DeepSeek to unauthorized extraction of proprietary capabilities from U.S. AI models and to evasion of U.S. semiconductor export controls, but the available information does not independently substantiate those allegations to the standard required to attribute cyber threat activity or specific operational capabilities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted large-scale model-distillation activity and silently proxied selected high-value customer coding sessions to Claude Opus, exposing sensitive user data while harvesting reasoning outputs for model training.
Allegedly conducts malicious model distillation and extraction of reasoning from U.S. AI models, using API access, proxy infrastructure, premium subscriptions, prompt injection, jailbreaks, metadata obfuscation, and automated collection.
DeepSeek is accused of creating fake data centers in Southeast Asia to pass regulatory audits and then diverting Nvidia GPUs to China, circumventing export controls.
DeepSeek is allegedly involved in a sophisticated smuggling operation to illegally obtain and operate thousands of Nvidia Blackwell GPUs, circumventing U.S. export controls. The group reportedly uses fake data centers and shell companies to acquire and transport restricted hardware into mainland China for AI model training and development.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.