Cyber security firm FireEye hit by 'state-sponsored' attack

The company says "highly sophisticated" hackers have breached its systems and made off with advanced penetration tools

A group of hackers behind the Russian flag

US cyber security firm FireEye, which is often used by governments to fend off state-sponsored attacks, has fallen victim to a hack that is believed to be the work of Russian actors

The company confirmed the attack on Tuesday, admitting that a "highly sophisticated state-sponsored adversary" had breached its systems and made off with advanced penetration tools

FireEye, which has 8,800 customers, didn't name which nation was behind the attack, but said the hackers had "top-tier offensive capabilities". It added that the case had been passed on to the FBI, which in turn, forwarded it on to a team of Russian specialists. 

The Bureau also confirmed the hack on Tuesday, but it didn't reveal which state was responsible. The organisation said that preliminary indications showed an "actor with a high level of sophistication consistent with a nation-state". 

Whoever the culprits are, the fear is that the stolen tools will be used in other sophisticated attacks on governments and other critical organisations. FireEye said it had "incorporated" countermeasures in its products which it has shared with partners and government agencies. 

"A highly sophisticated state-sponsored adversary stole FireEye Red Team tools," the firm said in a statement.

"Because we believe that an adversary possesses these tools, and we do not know whether the attacker intends to use the stolen tools themselves or publicly disclose them, FireEye is releasing hundreds of countermeasures to enable the broader security community to protect themselves against these tools." 

A 'Red Team' is a unit of security professionals that have the authorisation to mimic potential attacks and exploits on their own security systems or clients. FireEye's team works on large enterprise security and provides detailed analysis and advice on how to counter and prevent attacks. 

The tools taken range from simple scripts used for automating reconnaissance to entire frameworks for an attack, according to FireEye. Some of them are publicly available tools modified to evade basic security detection mechanisms, while other tools and frameworks were developed in-house for the company's Red Team.

Featured Resources

Virtual desktops and apps for dummies

An easy guide to virtual desktop infrastructure, end-user computing, and more

Download now

The total economic impact of optimising and managing your hybrid multi-cloud

Cost savings and business benefits of accelerating the cloud journey

Download now

A buyer’s guide for cloud-based phone solutions

Finding the right phone system for your modern business

Download now

What’s next for the education sector?

A new learning experience

Download now

Recommended

New report highlights the need for diversity in cyber security recruitment
cyber security

New report highlights the need for diversity in cyber security recruitment

28 Apr 2021
Biden calls for $22 billion in cyber security funding
Security

Biden calls for $22 billion in cyber security funding

18 May 2021
Avast’s Business Hub helps eliminate gaps in cyber defense
Security

Avast’s Business Hub helps eliminate gaps in cyber defense

18 May 2021
NETSCOUT threat intelligence report
Whitepaper

NETSCOUT threat intelligence report

18 May 2021

Most Popular

KPMG offers staff 'four-day fortnight' in hybrid work plans
flexible working

KPMG offers staff 'four-day fortnight' in hybrid work plans

6 May 2021
Hackers use open source Microsoft dev platform to deliver trojans
Security

Hackers use open source Microsoft dev platform to deliver trojans

14 May 2021
How to move Windows 10 from your old hard drive to SSD
operating systems

How to move Windows 10 from your old hard drive to SSD

30 Apr 2021