Itwerx is a managed IT and cybersecurity provider working with businesses in Seattle, Bellevue and Snohomish County since 2005. This traces how methods once reserved for state-level attackers reached ordinary criminals, and what that means for a smaller company.
From eleven years to about an hour
The first email worm was the Morris worm, in 1988. It took eleven years for the first overtly malicious version of the same idea to arrive – the Melissa worm, in 1999. That gap used to be how long it took for a new attack technique to be understood, copied and weaponized by the wider pool of bad actors.
That gap has collapsed. Most attackers today can fold a newly disclosed exploit into their existing toolkit within an hour or so of it becoming public. The one category that has resisted this speed-up is the Advanced Persistent Threat: a highly customized, individually targeted attack, historically requiring the kind of patient, human-led research that only a well-funded team – typically nation-state-adjacent – could justify.
What has been quietly automating in the background
The research phase of a targeted attack has been partially automated for years already, using OSINT (open-source intelligence) tooling such as Trape, Maltego and Datasploit. Historically that automation has been crude, producing raw material that still needed a skilled human to interpret and act on. That is the part that is changing: the same class of tooling is getting sophisticated enough that the human-assessment step, the thing that used to gate who could run an APT-style attack, is starting to fall away.
The forecast this argument made in March 2024 was specific: within a couple of years, an attack sophisticated enough to be mistaken for a nation-state operation could be launched by feeding little more than an email address or a social media profile link into an automated attack engine. That window is now mostly behind us rather than still ahead. This piece cannot settle from here whether every part of that forecast has landed exactly as described – but it is old enough now to be checked against events, rather than merely anticipated, and that is a meaningfully different position for a two-year-old prediction to be in.
The practical concern was never really the “kid in a basement” framing, either. It is the existing pool of well-resourced bad actors gaining access to tooling that used to require a nation-state’s research budget to operate at scale. Preparing for that shift, rather than waiting to see whether it arrives, is the more useful posture for a business to take.
Itwerx Corp is a service-disabled veteran-owned small business providing IT services across Seattle, Bellevue, Everett and Snohomish County. This is the kind of thing our cybersecurity work deals with – talk to us about yours.

