安全
前X-Force黑客追逐进攻性网络淘金热
RemoteThreat携700万美元资金、1,000款攻击工具及为AI速度运营装备企业与美国政府机构的雄心正式亮相
IBM X-Force Red团队的前两位领导人推出了RemoteThreat,这是一家获得700万美元种子前融资支持的进攻性网络安全初创公司。
首席执行官Chris Thompson和首席技术官Shawn Jones表示,该公司的平台利用人工智能来规划、执行和调整进攻性网络行动,超越了其他自动化工具所提供的持续渗透测试和漏洞检测功能。
Thompson和Jones此前曾领导X-Force Red团队,其团队受雇于测试核电站、关键基础设施和主要银行。2024年5月,Thompson向The Register透露了X-Force如何利用人工智能在八小时内攻破一家半导体制造商的网络。
随后,两人创立了Offensive AI Con,这是一个仅限邀请的研究活动,第二届会议定于10月初举行。
Thompson在接受The Register采访时说:“我们正在观察当前既嘈杂又极具能力的前沿模型,并开始思考:当它们能够像世界上最好的红队团队之一那样行事时,会发生什么?”
他表示,令人担忧的是,人工智能可能会生成接近国家级攻击者使用质量的定制恶意软件,然后以前所未有的速度和规模部署它。
RemoteThreat的15名员工包括来自X-Force Adversary Services、Mandiant、SpecterOps、Dreadnode、Bugcrowd、Microsoft、国防承包商和政府机构的高级操作员、安全研究人员、工程师和恶意软件开发者。
RemoteThreat表示,其平台使防御者和政府运营商能够获得AI可能向其对手提供的相同速度和规模。据该初创公司称,其客户已经包括一家大型银行、一家证券交易所运营商、一家美国大型医疗保健公司和一家领先的AI实验室。
Thompson说:“我们的重点是帮助这些财富500强组织更好地模拟这种国家级别的攻击。”“然后从另一方面来说,为政府提供工具,以便尽可能快地针对其对手。”
RemoteThreat将其平台描述为八个相连的系统,涵盖任务规划、指挥与控制、植入物、初始访问、高级攻击能力、混淆、分析和AI辅助操作。
鉴于滥用的明显潜力,RemoteThreat表示访问仅限于经过审查的企业、国防承包商和美国政府客户。
该平台针对某些任务使用小型专用模型。客户还可以连接来自OpenAI或Anthropic的模型,或使用开源替代方案,使所选LLM能够访问Thompson所说的“我们从零开始构建的1,000个工具”。
该平台可以由人类或AI代理操作。Thompson说:“客户可以‘通过你们的Codex终端驱动大量的测试工作,而不是必须登录我们的网站’。”
RemoteThreat表示,其功能可以在完整平台内运行,也可以作为合作伙伴产品的组件进行集成。该公司已与Talon Defense结盟,后者向国家安全、国防和情报客户提供AI和网络技术。
RemoteThreat还与Nakasone Group建立了合作伙伴关系,该国家安全咨询公司由退休的美国陆军上将Paul Nakasone创立,他曾任国家安全局局长和美国网络司令部司令。Nakasone也是该初创公司的战略顾问。
此次发布之际,华盛顿正寻求在进攻性网络行动中发挥更大的私营部门作用。今年3月发布的《美国网络战略》呼吁与业界在防御和进攻任务上加强合作。8月份的一份总统备忘录更进一步,下令创建一个项目,使经过审查的美国公司能够在联邦政府的指导和监督下,对外国网络犯罪集团实施网络行动。
RemoteThreat还称,其已加入美国特种作战司令部(USSOCOM)的“特种作战部队快速采购联盟以应对新兴需求”(SOF RACER),该联盟为向特种作战部队提供能力提供了渠道。
汤普森预计,政府将更广泛地使用商业开发的进攻性网络产品,既用于支持现有的任务团队,也用于追捕网络犯罪团伙。
他说:“这个领域有点像淘金热,因为这是第一次,在所有主要项目中,政府都被推动与商业部门合作。”
RemoteThreat正将自己定位为提供“镐头和铁锹”——尽管这些工具能够侵入他人的网络。®
security
Former X-Force hackers chase the offensive cyber gold rush
RemoteThreat launches with $7M, 1,000 attack tools, and ambitions to equip enterprises and Uncle Sam for AI-speed operations
Two former leaders of IBM's X-Force Red team have launched RemoteThreat, an offensive cybersecurity startup backed by $7 million in pre-seed funding.
CEO Chris Thompson and CTO Shawn Jones say the company's platform uses AI to plan, execute, and adapt offensive cyber operations, extending beyond the continuous penetration testing and vulnerability detection offered by other automated security tools.
Thompson and Jones previously ran X-Force Red, where their team was hired to test nuclear power plants, critical infrastructure, and major banks. In May 2024, Thompson told The Register how X-Force used AI to break into a semiconductor manufacturer's network in eight hours.
The pair subsequently created Offensive AI Con , an invitation-only research event whose second edition is scheduled for early October.
"We're looking at how noisy but very capable frontier models are right now, and we started to think: What happens when they can do what we can do as one of the best groups of red-teamers in the world?" Thompson told The Register in an interview.
He said the concern was that AI could produce custom malware approaching the quality used by state-sponsored attackers, then deploy it at unprecedented speed and scale.
RemoteThreat's 15 employees include senior operators, security researchers, engineers, and malware developers from X-Force Adversary Services, Mandiant, SpecterOps, Dreadnode, Bugcrowd, Microsoft, defense contractors, and government agencies.
RemoteThreat says its platform gives defenders and government operators access to the same speed and scale that AI may offer their adversaries. According to the startup, its customers already include a major bank, a securities exchange operator, a large US healthcare company, and a leading AI lab.
"We're focused on preparing these Fortune 500 organizations to better simulate this nation-state level of attack," Thompson said. "And then on the flip side, provide the government with the tooling to target their adversaries as quickly as possible."
RemoteThreat describes its platform as eight connected systems covering mission planning, command and control, implants, initial access, advanced attack capabilities, obfuscation, analysis, and AI-assisted operations.
Given the obvious potential for misuse, RemoteThreat says access is restricted to vetted enterprises, defense contractors, and US government customers.
The platform uses small, purpose-built models for some tasks. Customers can also connect models from OpenAI or Anthropic, or use an open-weight alternative, giving the chosen LLM access to what Thompson described as "1,000 tools that we've built from scratch."
The platform can be operated by either humans or AI agents. Customers can "drive a lot of this testing from your Codex terminal instead of having to log into our website, for example," Thompson said.
RemoteThreat says its capabilities can run within the complete platform or be integrated as components of partners' products. It has teamed up with Talon Defense, which supplies AI and cyber technology to national security, defense, and intelligence customers.
RemoteThreat has also partnered with the Nakasone Group, the national security advisory firm founded by retired US Army Gen. Paul Nakasone , former director of the National Security Agency and commander of US Cyber Command. Nakasone is also a strategic adviser to the startup.
The launch comes as Washington seeks a larger private-sector role in offensive cyber operations. The US Cyber Strategy published in March calls for closer cooperation with industry on defensive and offensive missions. An August presidential memorandum goes further, ordering the creation of a program through which vetted US companies may conduct cyber operations against foreign cybercrime groups under federal direction and oversight.
RemoteThreat also says it has joined US Special Operations Command's Special Operations Forces Rapid Acquisition Consortium for Emerging Requirements , or SOF RACER, which provides a route for supplying capabilities to special operations forces.
Thompson expects the government to make greater use of commercially developed offensive cyber products, both to support existing mission teams and to pursue cybercriminal groups.
"It's a bit of a gold rush in this space because this is the first time, across every major program, the government is being pushed to work with the commercial sector," he said.
RemoteThreat is positioning itself to supply the picks and shovels – albeit ones capable of breaking into somebody else's network. ®
首次收录 · 2026-09-30 · 8.43 分