
Telegram Bot Commands DeepSeek AI to Mount Autonomous Cyberattacks on Websites
A newly observed campaign uses Telegram to command DeepSeek AI, automating web attacks and posing a fresh challenge for website owners and hosting providers.
Security researchers have identified a novel attack technique in which a threat actor, reportedly of Chinese origin, uses the messaging app Telegram to command the DeepSeek AI platform to autonomously carry out cyberattacks against websites. The campaign marks a significant shift in the weaponization of generative AI, as it demonstrates how easily large language models can be integrated into malicious workflows with minimal human oversight.
The attack chain begins with a Telegram bot that sends prompts to DeepSeek's API, requesting the generation of exploit code tailored to specific vulnerabilities in web applications. Once the AI produces functional attack scripts, the bot automatically deploys them against targeted sites, often scanning for common flaws such as SQL injection, cross-site scripting, or insecure file uploads. The use of Telegram as a command-and-control channel provides anonymity and ease of operation, allowing the attacker to manage the campaign remotely without exposing their own infrastructure.
For website owners and hosting providers, this development raises the stakes significantly. Autonomous AI-powered attacks can scan and exploit vulnerabilities at machine speed, overwhelming traditional patching cycles and manual security reviews. Even sites with basic protections may find themselves breached if they rely solely on perimeter defenses, as the AI can rapidly adapt and retry different payloads.
To defend against such threats, a layered security approach is essential. Regular software updates, web application firewalls, and intrusion detection systems remain critical, but the dynamic nature of AI-generated attacks calls for proactive monitoring and automated response. For site owners, employing a security-hardened hosting environment like AEU Hosting can provide robust defenses by automatically patching vulnerabilities and monitoring for suspicious activity, reducing the risk of automated AI-driven exploits. Additionally, implementing strict API security, scrutinizing AI-generated traffic, and leveraging DNS-level filtering can help blunt these emerging attack vectors.