DeepSeek
DeepSeek is a prominent Chinese AI company alleged to have illegally acquired and operated several thousand Nvidia Blackwell GPUs by circumventing U.S. export restrictions. According to multiple sources, DeepSeek is involved in a sophisticated smuggling operation that uses shell companies to purchase Nvidia servers in Southeast Asia, establish fake data centers to pass OEM inspections, and subsequently disassemble and smuggle the GPU servers into mainland China. The operation reportedly favors 8-GPU rack servers such as the HGX B200 for ease of transport. DeepSeek has a history of stockpiling and purchasing large numbers of Nvidia GPUs for AI model training, as domestic alternatives like Huawei's Ascend servers have proven inadequate for their needs. While DeepSeek uses Huawei Ascend servers for inference, it relies on Nvidia hardware for training large language models, such as its R1 LLM trained on 2,048 Nvidia H800s. These activities, if substantiated, would represent a direct attempt to bypass U.S. export controls on advanced AI hardware. There is no indication that DeepSeek is a nation-state actor, but its actions are highly relevant in the context of the ongoing U.S.-China "Chip War" and the broader geopolitical struggle over advanced compute hardware. No known aliases or sub-groups are mentioned in the available content.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Recent activity
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DeepSeek is accused of creating fake data centers in Southeast Asia to pass regulatory audits and then diverting Nvidia GPUs to China, circumventing export controls.
DeepSeek is allegedly involved in a sophisticated smuggling operation to illegally obtain and operate thousands of Nvidia Blackwell GPUs, circumventing U.S. export controls. The group reportedly uses fake data centers and shell companies to acquire and transport restricted hardware into mainland China for AI model training and development.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.