Two former leaders of IBM's X-Force Red team have launched RemoteThreat, an offensive cybersecurity startup backed by $7 million in pre-seed funding. CEO Chris Thompson and CTO Shawn Jones say the company's platform uses AI to plan, execute, and adapt offensive cyber operations, moving beyond the continuous penetration testing and vulnerability detection offered by other automated security tools. The startup aims to equip both enterprises and government agencies for what Thompson calls AI-speed operations.

RemoteThreat's platform includes eight connected systems that cover mission planning, command and control, implants, initial access, advanced attack capabilities, obfuscation, analysis, and AI-assisted operations. The company says it has built 1,000 tools from scratch that can be accessed through its platform. The 15-person team includes senior operators, security researchers, engineers, and malware developers drawn from X-Force Adversary Services, Mandiant, SpecterOps, Dreadnode, Bugcrowd, Microsoft, defense contractors, and government agencies. Customers already include a major bank, a securities exchange operator, a large US healthcare company, and a leading AI lab. The platform can be operated by either humans or AI agents, and customers can drive testing from a terminal rather than logging into the website.

Thompson told The Register his team began asking what would happen "when they can do what we can do as one of the best groups of red-teamers in the world." He said the worry was that AI could create custom malware approaching the quality used by state-sponsored attackers, then deploy it at unprecedented speed and scale. According to Thompson, the company focuses on preparing Fortune 500 organizations to better simulate nation-state level attacks, while providing the government with tools to target their adversaries as quickly as possible. The platform uses small, purpose-built models for some tasks, and customers can also connect models from OpenAI or Anthropic, or use an open-weight alternative.

The launch comes as Washington pushes for a larger private-sector role in offensive cyber operations. The US Cyber Strategy published in March calls for closer cooperation with industry on defensive and offensive missions, according to the report. An August presidential memorandum goes further, ordering the creation of a program through which vetted US companies may conduct cyber operations against foreign cybercrime groups under federal direction and oversight. RemoteThreat has partnered with Talon Defense, which supplies AI and cyber technology to national security customers, and with the Nakasone Group, the advisory firm founded by retired US Army Gen. Paul Nakasone, former NSA director and US Cyber Command commander. Nakasone also serves as a strategic adviser to the startup.

Given the obvious potential for misuse, RemoteThreat says access is restricted to vetted enterprises, defense contractors, and US government customers. The company has joined US Special Operations Command's Special Operations Forces Rapid Acquisition Consortium for Emerging Requirements, which provides a route for supplying capabilities to special operations forces. Thompson expects the government to make greater use of commercially developed offensive cyber products, both to support existing mission teams and to pursue cybercriminal groups. "It's a bit of a gold rush in this space because this is the first time, across every major program, the government is being pushed to work with the commercial sector," he said. The company is positioning itself to supply the tools for breaking into networks as Washington seeks private partners for offensive operations. The underlying bet is that offensive capabilities can no longer remain exclusively within government walls when adversaries are racing to automate attack at machine speed, and that controlled commercial access under strict vetting may prove the only viable counter.