This past week we finally got to reveal our most recent investment when RemoteThreat emerged from stealth with $7M raised and the official launch of its integrated offensive cyber operations platform.
It’s not news to anyone that AI has simultaneously changed how quickly attacks happen and who can execute attacks. While models have become increasingly capable, we believe the most capable operations will pair advanced AI offensive tooling and the most capable human operators. Building and preparing for that world takes deep exploit experience, practical AI fluency, and trust with enterprise and government customers, a combination that took us years to find; when we met Chris Thompson, Shawn Jones, and their team, we knew we’d found it. It also helped that DataTribe Venture Partner Rob Joyce, former NSA Director of Cybersecurity, thinks so highly of them.
The public data from the past year is clear: attacks are getting faster, and sophisticated campaigns take fewer people to run. CrowdStrike’s 2026 Global Threat Report puts average eCrime breakout time at 29 minutes, with the fastest at 27 seconds, alongside an 89% rise in activity from AI-enabled adversaries. Mandiant’s M-Trends 2026 estimates mean time to exploit at negative seven days, down from 63 days in 2018, and Verizon’s 2026 DBIR ranks vulnerability exploitation as the top way in for the first time.
AI is doing more of the work, too. In the GTG-1002 espionage campaign disrupted by Anthropic, AI handled an estimated 80–90% of the tactical work, and Anthropic’s September 2026 report says AI has narrowed the gap between state-level and individual operators. Traditional red team tooling wasn’t built to keep up.
Today’s autonomous agents are fast but uneven. Security teams at Black Hat and ServiceNow describe the typical offensive AI agent as conspicuous and relatively easy to stop, and SentinelLabs counted roughly 17,600 actions in one agent-driven intrusion this summer, most of which failed. In a Stanford/CMU study, the best AI agent outperformed 9 of 10 professional testers, though the top human still did better.
Those gaps will narrow as models improve, and that’s where Remote Threat will become even more important; capable actors are already adapting: ServiceNow researchers observed a China-linked group that deliberately slowed its AI agents to avoid detection while running noisy decoys. As AI becomes more capable, the advantage increasingly comes from combining it with advanced offensive tooling, operational context, and expert judgment. RemoteThreat is built to capitalize on those advances while giving teams control over how capabilities are used.
A company building for this world needs hands-on offensive depth, practical AI fluency, and the trust to put powerful tooling in customers’ hands. Plenty of teams have one or two of these but finding all three in a founding team is less common, and it’s what gave us the conviction to back this team.
If you’ve been around cyber over the past two decades, there’s a good chance you’ve met or worked with Chris and Shawn. Chris led IBM X-Force’s Adversary Services team, where Shawn led capability research and development, and their team was hired to test nuclear plants, critical infrastructure, and major banks. That DNA runs through RemoteThreat’s 16-person team, drawn from X-Force, Mandiant, SpecterOps, Dreadnode, Bugcrowd, Microsoft, and government service.
They also got to AI early. The team was using AI to break into hardened networks back in 2024, and Chris founded Offensive AI Con to bring the field’s researchers together in a first of its kind event. RemoteThreat’s approach combines advanced offensive capabilities with governed AI workflows, alongside ongoing development of specialized models for offensive cyber tasks.
At its heart, RemoteThreat translates the team’s expertise into an integrated operating environment spanning mission planning, native command-and-control, implants, initial access, advanced capabilities, obfuscation, analysis, and AI-assisted operation. Its composable capabilities are designed for use by both human operators and AI workflows, and for integration into customers’ and partners’ existing platforms. That combination of offensive research, capability engineering, and operational integration is the foundation of its differentiation.
At DataTribe, one of our core sayings has always been, “Offense to Defense.” The idea is pretty straightforward; you can’t stop an adversary if you can’t think like one. RemoteThreat gives enterprise red teams a way to test defenses against what’s coming and gives authorized government mission teams capabilities built by people who have done the work. We are also seeing policy moving the same way: the March 2026 US Cyber Strategy calls for deeper industry partnership, and an August presidential memorandum creates a path for vetted companies to support operations against foreign cybercrime groups.
We expect the need for what RemoteThreat is building to keep growing as AI compresses attack timelines and enterprises and government alike turn to industry to keep pace. Chris, Shawn, and the team have spent their careers adapting to adversaries that change quickly. We’re glad to be partnering with them and look forward to supporting them as they build.
Read the Business Wire press release: RemoteThreat Emerges from Stealh