Eastern AI models close the gap on Western rivals at a fifth of the cost, Ensign InfoSecurity finds
Ensign InfoSecurity ran ten frontier models through 160 attack runs against a defended network, and the cheapest models returned the most capability per dollar.
Security teams have long worked on the assumption that the most capable AI-enabled attacks would be built around the strongest Western models, which are also the most expensive to run. New testing from Ensign InfoSecurity suggests that assumption is now out of date.
In the AI Cyber Range Assessment published in its 2026 Cyber Threat Landscape Report, Ensign found that GLM-5.2, from China's Z.AI, matched OpenAI's GPT-5.6 Sol and Anthropic's Claude Opus 4.8 on offensive performance while costing roughly a fifth as much to operate.
Ensign has been evaluating models from both regions since April 2026. The report says it started from every generally available model validated against benchmarks such as CyberGym and ExploitGym, giving more than 150 candidates, and took the ten scoring above the 95th percentile through to detailed evaluation. Five came from Western developers in OpenAI, Anthropic, Google, Meta and xAI, and five from Eastern developers in Z.AI, Moonshot AI, Alibaba, DeepSeek and MiniMax.
Ensign built the test environment to look like a university network, with an online learning portal at the front and the systems that manage staff and student logins behind it, running the monitoring and endpoint detection software most organisations already use. Every model was given the same eight objectives and the same instructions, with nothing rewritten to suit any one of them. Each ran 16 times, against a network reset to its starting state before every run.
Three models pulled ahead
GPT-5.6 Sol, Opus 4.8 and GLM-5.2 recorded High Success on seven of the eight objectives, defined by the report as achieving the objective in at least eight of 16 runs. Only six of the ten models cleared all eight objectives in two or more runs.
The cost separation was wider than the capability separation. Ensign put GPT-5.6 Sol at US$1,250 per 100 million tokens against US$230 for GLM-5.2. On the report's measure of objective success per US$1,000, Eastern models delivered significantly higher capability per dollar overall, with GLM-5.2 returning 408 against GPT-5.6 Sol's 75, roughly five times as much.
The pattern was not uniform. Moonshot AI's Kimi K3 scored 114, below three of the five Western models on the same measure. Ensign's conclusion is that threat models built around restricted Western models now understate the exposure, since a model performing at that level can be downloaded and run at a fraction of the price.
Where the models failed
Breaching the portal worked in every run across every model, giving that objective 100% mean reliability. Bypassing endpoint detection and response (EDR) at runtime was the weakest result at 40%, with no model reaching High Success and only six managing partial success. Lateral movement came in at 67.5%.
Ensign's reading is that monitoring should be treated as a necessity rather than an assurance, and that behavioural anomaly detection reinforced by deterministic controls is the more durable defence.
It also points to token economics as a lever defenders still hold, since choke points that force repeated attempts raise the attacker's cost per outcome, while cautioning that the advantage should be expected to erode as models improve.
"In our testing, comparable offensive capability was available at roughly a fifth of the price, and defenders should assume the pool of adversaries will keep growing," said Jeremy Moke, EnSOC director at Ensign InfoSecurity Malaysia.
"Frontier AI is changing the speed, scale and economics of cyberattacks with capability advancing on an estimated two-month cycle, and organisations need to continuously reassess how they measure cyber risk and resilience, not just how much they spend on controls,” Moke added.
Ensign describes its own findings as indicative of model capability against defences rather than definitive, noting that the range does not reproduce the legacy systems and accepted vulnerabilities that persist in a working enterprise. Its recommendation is to re-test defences against current models on a set cadence.
Ensign's scorecard is dated August 13, 2026. Z.AI released GLM-5.3 the next day, marketed on coding and cybersecurity work, with the full model's weights held back pending safety evaluation.
AI-enabled threat landscape
The report also revealed that frontier AI is making sophisticated attacks more accessible, with cyber attackers relying on living-off-the-land techniques that can be difficult to distinguish from legitimate activity.
Specfically, AI is acting as a force multiplier rather than replacing existing tradecraft. For example, AI enabled ransomware is accelerating reconnaissance, identifying vulnerabilities and crafting more convincing phishing lures, making attacks faster, more sophisticated and easier to repeat. The impact differs across regions.
In the ASEAN region, ransomware activity doubled in 2025, with the top 18 ransomware groups targeting the region. Over in Australasia and East Asia, ransomware activity has increased by more than 600% and 400% respectively, driven by the most mature and capable ransomware groups.
Apart from ransomware, data theft is increasingly replacing encryption as the primary driver of cyberattacks. Edge devices, remote access infrastructure and third-party suppliers remain common entry points into organisations, exploiting vulnerabilities that have remained unpatched for years.
Singapore provides a compelling example of this shift, with the highest underground value attributed to Singaporean 1Fullz identity package at USD 95. This is more than three times its price in 2023 at US$30.
The ASEAN region also recorded the highest level of hacktivist activity, with targets going beyond government organisations to include critical infrastructure, including utilities, energy, transportation and telecommunications providers. Banking, Finance & Insurance, Manufacturing & Industrial and Telecommunications, Media and Technology remained among the most targeted sectors due to the value of their data and operational importance.
Acording to Xiang Zheng Teo, Vice President of Advisory at Ensign InfoSecurity, leading frontier AI models are already capable of executing multiple stages of a cyberattack chain more quickly and at a lower cost.
He shared that the threat is further intensified as the capability gap between models continues to narrow, and cost may soon cease to be a barrier for threat actors. Frontier AI is fundamentally changing the speed, scale and economics of cyberattacks, requiring organisations to rethink how they assess cyber risk and resilience.
“Organisations should strengthen their cybersecurity foundations by prioritising the scanning and patching of critical internet-facing assets and continuously validating their defences against the latest AI models. With frontier AI capabilities advancing on a roughly two-month cycle, security controls cannot afford to remain static. Agility and dynamism in cyber defence defines the good cyber defender from the rest,” he said.