AIRLINK 79.41 Increased By ▲ 1.02 (1.3%)
BOP 5.33 Decreased By ▼ -0.01 (-0.19%)
CNERGY 4.38 Increased By ▲ 0.05 (1.15%)
DFML 33.19 Increased By ▲ 2.32 (7.52%)
DGKC 76.87 Decreased By ▼ -1.64 (-2.09%)
FCCL 20.53 Decreased By ▼ -0.05 (-0.24%)
FFBL 31.40 Decreased By ▼ -0.90 (-2.79%)
FFL 9.85 Decreased By ▼ -0.37 (-3.62%)
GGL 10.25 Decreased By ▼ -0.04 (-0.39%)
HBL 117.93 Decreased By ▼ -0.57 (-0.48%)
HUBC 134.10 Decreased By ▼ -1.00 (-0.74%)
HUMNL 7.00 Increased By ▲ 0.13 (1.89%)
KEL 4.67 Increased By ▲ 0.50 (11.99%)
KOSM 4.74 Increased By ▲ 0.01 (0.21%)
MLCF 37.44 Decreased By ▼ -1.23 (-3.18%)
OGDC 136.70 Increased By ▲ 1.85 (1.37%)
PAEL 23.15 Decreased By ▼ -0.25 (-1.07%)
PIAA 26.55 Decreased By ▼ -0.09 (-0.34%)
PIBTL 7.00 Decreased By ▼ -0.02 (-0.28%)
PPL 113.75 Increased By ▲ 0.30 (0.26%)
PRL 27.52 Decreased By ▼ -0.21 (-0.76%)
PTC 14.75 Increased By ▲ 0.15 (1.03%)
SEARL 57.20 Increased By ▲ 0.70 (1.24%)
SNGP 67.50 Increased By ▲ 1.20 (1.81%)
SSGC 11.09 Increased By ▲ 0.15 (1.37%)
TELE 9.23 Increased By ▲ 0.08 (0.87%)
TPLP 11.56 Decreased By ▼ -0.11 (-0.94%)
TRG 72.10 Increased By ▲ 0.67 (0.94%)
UNITY 24.82 Increased By ▲ 0.31 (1.26%)
WTL 1.40 Increased By ▲ 0.07 (5.26%)
BR100 7,526 Increased By 32.9 (0.44%)
BR30 24,650 Increased By 91.4 (0.37%)
KSE100 71,971 Decreased By -80.5 (-0.11%)
KSE30 23,749 Decreased By -58.8 (-0.25%)
World

U.S. cybersecurity firm FireEye discloses breach, theft of internal hacking tools

  • Kevin Mandia said “red team tools” were stolen as part of a highly sophisticated, likely “nation-state” hacking operation.
  • The hackers also appeared to be interested in a subset of FireEye customers: government agencies.
Published December 9, 2020

FireEye, one of the largest cybersecurity companies in the United States, said on Tuesday that is has been hacked, possibly by a government, leading to the theft of an arsenal of internal hacking tools typically reserved to privately test the cyber defenses of their own clients.

The hack of FireEye, a company with an array of business contracts across the national security space both in the United States and its allies, is among the most significant breaches in recent memory.

The FireEye breach was disclosed in a blog post authored by CEO Kevin Mandia. The post said “red team tools” were stolen as part of a highly sophisticated, likely “nation-state” hacking operation. It is not clear exactly when the hack initially took place.

Beyond the tool theft, the hackers also appeared to be interested in a subset of FireEye customers: government agencies.

“We hope that by sharing the details of our investigation, the entire community will be better equipped to fight and defeat cyber attacks,” Mandia wrote.

The company itself has partnered in recent weeks with different software makers to share defensive measures.

There is no evidence yet that FireEye’s hacking tools have been used or that client data was exfiltrated. But the investigation, which includes help from the Federal Bureau of Investigation and Microsoft Corp, is in its early phases.

“This incident demonstrates why the security industry must work together to defend against and respond to threats posed by well-funded adversaries using novel and sophisticated attack techniques,” a Microsoft spokesperson said.

The FBI did not immediately respond to a request for comment.

The stolen computer espionage kit targets a myriad of different vulnerabilities in popular software products. It is not yet clear exactly which systems may be affected.

But Mandia wrote that none of the red team tools exploited so-called “zero day vulnerabilities,” meaning the relevant flaws should already be public.

Experts say it can be difficult to measure the impact of a hacking tool leak which focuses on known software vulnerabilities. Whenever a private company becomes aware of a vulnerability in their software product they often try to offer a “patch” or upgrade that nullifies the issue. Yet users do not always download these patches quickly, leaving themselves exposed for months or weeks.

“We are not sure if the attacker intends to use our Red Team tools or to publicly disclose them,” Mandia wrote.

Comments

Comments are closed.