"We're focused on preparing these Fortune 500 organizations to better simulate this nation-state level of attack," Thompson said.
Chris Thompson, Shawn Jones, and the X‑Force Red pedigree
RemoteThreat was launched by two former leaders of IBM's X‑Force Red team: CEO Chris Thompson and CTO Shawn Jones. The pair previously ran X‑Force Red, where their team was hired to test nuclear power plants, critical infrastructure, and major banks. In May 2024, Thompson told The Register how X‑Force used AI to break into a semiconductor manufacturer's network in eight hours. The new startup employs 15 people drawn from X‑Force Adversary Services, Mandiant, SpecterOps, Dreadnode, Bugcrowd, Microsoft, defense contractors, and government agencies.
Platform design: eight connected systems and mixed AI
RemoteThreat describes its product as a platform made up of eight connected systems covering mission planning, command and control, implants, initial access, advanced attack capabilities, obfuscation, analysis, and AI‑assisted operations. The company says the platform uses small, purpose‑built models for some tasks while allowing customers to connect models from OpenAI or Anthropic, or an open‑weight alternative. Thompson described giving a chosen large language model access to "1,000 tools that we've built from scratch." The platform can be operated by humans or AI agents, and customers can interact with it through different interfaces, for example by driving testing "from your Codex terminal instead of having to log into our website."

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadCustomers, partners, and $7 million pre‑seed backing
RemoteThreat launched with $7 million in pre‑seed funding. The startup says its customer list already includes a major bank, a securities exchange operator, a large US healthcare company, and a leading AI lab. On the partnerships side, RemoteThreat has teamed up with Talon Defense and the Nakasone Group; retired US Army Gen. Paul Nakasone, founder of the Nakasone Group and former director of the National Security Agency and commander of US Cyber Command, serves as a strategic adviser to the startup. RemoteThreat also says it has joined US Special Operations Command's Special Operations Forces Rapid Acquisition Consortium for Emerging Requirements, or SOF RACER, which the company notes provides a route for supplying capabilities to special operations forces.
Positioning against state‑level threats and commercial demand
Thompson and Jones framed RemoteThreat's offering as a response to the risk that AI will enable adversaries to create high‑quality custom malware and deploy it at scale and speed. Thompson told The Register the team began asking: "What happens when they can do what we can do as one of the best groups of red‑teamers in the world?" RemoteThreat says its aim is to give defenders and government operators access to the speed and scale that AI may offer attackers, positioning the product as a way to simulate nation‑state level attacks for Fortune 500 organizations and to provide tooling "to target their adversaries as quickly as possible." The company also highlights the ability to integrate its capabilities within partner products or to run them entirely inside the RemoteThreat platform.
US policy moves and the commercial offensive market
The launch comes as Washington signals a larger private‑sector role in offensive cyber operations. The US Cyber Strategy published in March calls for closer cooperation with industry on defensive and offensive missions, and an August presidential memorandum ordered creation of a program through which vetted US companies may conduct cyber operations against foreign cybercrime groups under federal direction and oversight. Thompson expects the government to make greater use of commercially developed offensive cyber products across programs, and he described the current moment as "a bit of a gold rush in this space" because federal programs are pushing for increased commercial engagement.
Restrictions, misuse risk, and the next public convening
RemoteThreat acknowledges the "obvious potential for misuse" of offensive tools and says access to the platform is restricted to vetted enterprises, defense contractors, and US government customers. The company also runs Offensive AI Con, an invitation‑only research event it created; the second edition is scheduled for early October. RemoteThreat characterizes its role as supplying the "picks and shovels" of offensive cyber capability—tools that, by design, can break into other networks—while asserting controls on who may access them.
What this means for technologists, policymakers, and special operations forces
- Technologists and security teams: Expect a new set of commercially available offensive tools that combine AI agents, purpose‑built models, and a large set of bespoke tooling; companies already using RemoteThreat include a major bank and a securities exchange operator.
- Policymakers and procurement leaders: The startup arrives amid explicit US policy moves to increase industry participation in offensive missions, including a presidential memorandum creating a vetting program for private companies to act under federal direction.
- Government mission teams and special operations forces: RemoteThreat has joined SOF RACER and positioned itself to supply capabilities to special operations and other federal mission teams that are pursuing criminal and adversary‑oriented cyber objectives.
RemoteThreat's rapid launch, partner list, and links to federal acquisition channels make its next public milestones—Offensive AI Con in early October and any work flowing through SOF RACER—clear points to watch. The company frames its offering as preemptive: build the offensive tools commercially so defenders and government operators can match the speed and scale its founders say AI may soon put in adversaries' hands. Whether those restrictions and vetting processes will be sufficient to govern similar tooling at scale is a question the platform's early customers and government partners will now confront.




