Ensign: Advanced AI Models Can Easily Launch Cyber Attacks
Jakarta (ANTARA) - Cybersecurity firm Ensign InfoSecurity has stated that advanced Artificial Intelligence (AI) models are capable of executing sequences of cyber attacks with ease.
“With agentic AI, we are no longer just opening a web browser, using ChatGPT, typing a prompt, and receiving an answer. Now, the AI lives within the computer. This means it can read files and even write code, making it much more dynamic,” said Adithya Nugputra, Head of Consulting at Ensign InfoSecurity Indonesia, in Jakarta on Wednesday.
Ensign InfoSecurity presented these findings regarding the capabilities of various AI models in the seventh edition of its 2026 Cyber Threat Landscape Report.
From over 150 publicly available AI models, the company selected 10 models for testing. The tested models included those from Western technology companies, such as OpenAI’s GPT-5.6 Sol, Anthropic’s Claude Opus 4.8, Google’s Gemini 3.5 Flash, Meta’s Muse Spark, and xAI’s Grok 4.5.
The company also tested models from Chinese firms, including Z.AI’s GLM-5.2, Moonshot’s Kimi K3, Alibaba’s Qwen 3.8 Max, DeepSeek’s V-4-Pro, and MiniMax’s M3.
The test results indicate that advanced AI models can reduce the costs, time, and expertise required to carry out complex cyber attacks. Ensign also found that the capabilities of AI models from various countries are becoming increasingly similar, making operational costs a decisive factor for cybercriminals when choosing an AI model to execute attacks.
During the testing, the ten selected AI models were positioned as cyber attackers and assigned eight identical attack objectives. These objectives included gaining network access, accessing sensitive data, bypassing network restrictions, taking over trusted systems, stealing credentials for system login, performing lateral movement between systems, evading security detection, and maintaining long-term access to systems.
GPT-5.6 Sol, Claude Opus 4.8, and GLM 5.2 emerged as the highest-performing models during the testing, showing high success rates in seven out of the eight tested attack objectives. Ensign noted that the GLM-5.2 model possessed attack capabilities comparable to GPT-5.6, but its operational costs were one-fifth lower.
“AI models from the East have narrowed the gap with Western models and demonstrated equivalent capabilities,” said Adithya.
However, AI capabilities are not yet fully reliable for executing attacks into deeper stages of a target system. Although all tested models successfully gained initial access to their targets, at least half of the AI models struggled when attempting to steal credentials and move from one system to another.
None of the ten tested models were able to achieve a high success rate in evading Endpoint Detection and Response (EDR) security systems during an ongoing attack.
“So, all 10 AI models succeeded in gaining network access; they all got in. However, their capability decreased when they had to move into deeper systems,” said Adithya.
These findings highlight the urgent need for enhanced digital system security. Ensign suggested that strong identity controls, network segmentation, and behavioural monitoring can make it more difficult for attackers to move further and exploit initial access to expand attacks to other systems.