Two former IBM X-Force Red leaders have launched RemoteThreat, an offensive cybersecurity startup backed by $7 million in pre-seed funding. The platform uses AI to plan and execute cyber operations, helping enterprises simulate nation-state attacks and providing U.S. government customers with advanced offensive capabilities against adversaries.

News article

Former IBM X-Force Red Leaders Launch AI-Driven Offensive Cybersecurity Startup

Chris Thompson and Shawn Jones, former leaders of IBM X-Force Red, have launched RemoteThreat with $7 million in pre-seed funding

1

2

. The offensive cybersecurity startup offers what it calls the first commercial end-to-end solution for offensive cyber operations, targeting enterprise red teams and U.S. government customers. Osage University Partners and DataTribe co-led the pre-seed round

2

.

Thompson serves as CEO while Jones takes the CTO role at RemoteThreat. Both previously ran X-Force Red, where their team tested security for nuclear power plants, critical infrastructure providers, and major banks

1

. In May 2024, Thompson demonstrated how X-Force Red used AI to breach a semiconductor manufacturer's network in just eight hours

1

. The pair also created Offensive AI Con, an invitation-only research event with its second edition scheduled for early October

1

.

Platform Uses AI Models to Simulate Nation-State-Level Attacks

RemoteThreat's cyber operations platform extends beyond continuous penetration testing and vulnerability detection offered by other automated security tools. Thompson explained the motivation: "We're looking at how noisy but very capable frontier models are right now, and we started to think: What happens when they can do what we can do as one of the best groups of red-teamers in the world?"

1

. The concern centers on AI producing custom malware approaching state-sponsored attacker quality, then deploying it at unprecedented speed and scale.

The platform comprises eight connected systems covering mission planning, command and control, implants, initial access, advanced attack capabilities, obfuscation, analysis, and AI-assisted operations

1

. It uses small, purpose-built models for specific tasks while allowing customers to connect models from OpenAI or Anthropic, or use open-weight alternatives. The chosen LLM gains access to "1,000 tools that we've built from scratch," according to Thompson

1

.

Enterprise Red Teams and Government Operators Gain Advanced Capabilities

RemoteThreat's 15 employees include senior operators, security researchers, engineers, and malware developers from X-Force Adversary Services, Mandiant, SpecterOps, Dreadnode, Bugcrowd, Microsoft, defense contractors, and government agencies

1

. Jones emphasized that "internal red teams are being asked to model adversaries whose capabilities change faster than the tools used to emulate them," adding that "the answer is not another black-box, automated penetration testing tool that removes the operator"

2

.

The platform can be operated by either humans or AI agents, with customers able to "drive a lot of this testing from your Codex terminal instead of having to log into our website," Thompson noted

1

. RemoteThreat says its customers already include a major bank, a securities exchange operator, a large U.S. healthcare company, and a leading AI lab

1

. Thompson stated the company is "focused on preparing these Fortune 500 organizations to better simulate this nation-state level of attack"

1

.

Strategic Partnerships Position RemoteThreat for Government Contracts

Given the potential for misuse, RemoteThreat restricts access to vetted enterprises, defense contractors, and U.S. government customers

1

. The startup has partnered with Talon Defense, which supplies AI and cyber technology to national security, defense, and intelligence customers

1

2

. RemoteThreat's capabilities can run within the complete platform or be integrated as components of partners' products

1

.

The Nakasone Group, founded by retired U.S. Army Gen. Paul Nakasone, former director of the National Security Agency and commander of U.S. Cyber Command, serves as a strategic adviser

1

2

. Nakasone said RemoteThreat's team can make "a meaningful contribution to national security and enterprise defense," citing its offensive experience and custom AI models

2

. RemoteThreat has also joined U.S. Special Operations Command's SOF RACER, which provides a route for supplying capabilities to special operations forces

1

2

.

Launch Aligns With Expanding Government Role for Private Sector Offensive Capabilities

The launch comes as Washington seeks a larger private-sector role in offensive cyber operations. The U.S. Cyber Strategy published in March calls for closer cooperation with industry on defensive and offensive missions

1

. An August presidential memorandum goes further, ordering the creation of a program through which vetted U.S. companies may conduct cyber operations against foreign cybercriminal groups under federal direction and oversight

1

2

.

The Senate's fiscal 2027 defense authorization bill includes a trial program that would let private companies gain and maintain access to adversary networks under U.S. Cyber Command authority

2

. Thompson expects the government to make greater use of commercially developed offensive cyber products, both to support existing mission teams and to pursue cybercriminal groups. "It's a bit of a gold rush in this space because this is the first time, across every major program, the government is being pushed to work with the commercial sector," he said

1

. Marc Singer, managing partner at Osage University Partners, said the founders' experience running operations against "the world's hardest targets" gave them an early read on where the market was headed

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved