Cybersecurity Firm FireEye Got Hacked; Red-Team Pentest Tools Stolen
Ravie LakshmananDec 09, 2020
FireEye, one of the largest cybersecurity firms in the world, said on Tuesday it became a victim of a state-sponsored attack by a "highly sophisticated threat actor" that stole its arsenal of Red Team penetration testing tools it uses to test the defenses of its customers.
The company said it's actively investigating the breach in coordination with the US Federal Bureau of Investigation (FBI) and other key partners, including Microsoft.
It did not identify a specific culprit who might be behind the breach or disclose when the hack exactly took place.
However, The New York Times and The Washington Post reported that the FBI has turned over the investigation to its Russian specialists and that the attack is likely the work of APT29 (or Cozy Bear) — state-sponsored hackers affiliated with Russia's SVR Foreign Intelligence Service — citing unnamed sources.
As of writing, the hacking tools have not been exploited in the wild, nor do they contain zero-day exploits, although malicious actors in possession of these tools could abuse them to subvert security barriers and take control of targeted systems.
Red Team tools are often used by cybersecurity organizations to mimic those used in real-world attacks with the goal of assessing a company's detection and response capabilities and evaluating the security posture of enterprise systems.
The company said the adversary also accessed some internal systems and primarily sought information about government clients but added there's no evidence that the attacker exfiltrated customer information related to incident response or consulting engagements or the metadata collected by its security software.
"This attack is different from the tens of thousands of incidents we have responded to throughout the years," FireEye CEO Kevin Mandia wrote in a blog post.
"The attackers tailored their world-class capabilities specifically to target and attack FireEye. They are highly trained in operational security and executed with discipline and focus. They operated clandestinely, using methods that counter security tools and forensic examination. They used a novel combination of techniques not witnessed by us or our partners in the past."
The accessed Red Team tools run the gamut from scripts used for automating reconnaissance to entire frameworks that are similar to publicly available technologies such as CobaltStrike and Metasploit. A few others are modified versions of publicly available tools designed to evade basic security detection mechanisms, while the rest are proprietary attack utilities developed in-house.
To minimize the potential impact of the theft of these tools, the company has also released 300 countermeasures, including a list of 16 previously disclosed critical flaws that should be addressed to limit the effectiveness of the Red Team tools.
If anything, the development is yet another indication that no companies, counting cybersecurity firms, are immune to targeted attacks.
Major cybersecurity firms such as Kaspersky Lab, RSA Security, Avast, and Bit9 have previously fallen victims to damaging hacks over the past decade.
The incident also bears faint similarities to The Shadow Brokers' leak of offensive hacking tools used by the US National Security Agency in 2016, which also included the EternalBlue zero-day exploit that was later weaponized to distribute the WannaCry ransomware.
"Security companies are a prime target for nation-state operators for many reasons, but not least of all is [the] ability to gain valuable insights about how to bypass security controls within their ultimate targets," Crowdstrike's co-founder and former CTO Dmitri Alperovitch said.
The release of red team tools stolen by the adversary "will go a long way to mitigating the potential impact of this intrusion for organizations all over the world," he added.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
SHARE
Tweet
Share
Share
SHARE
data breach, hacking news, Penetration Testing, Pentesting Tools, Red Team, Vulrebility Assessment
⚡ Top Stories This Week
New DirtyClone Linux Kernel Flaw Lets Local Users Gain Root via Cloned Packets
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries
Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data
FBI Warns Russian Intelligence Hackers Target Signal Backup Recovery Keys
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private
Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
Load More ▼
⭐ Featured Resources
Get Hands-On SANS Training for Today’s Cyber Defense and Offensive Security Challenges
Get Gartner’s Guide to AI Agent Supervision and Runtime Controls
What 200+ Security Teams Reveal About Using IP Intelligence in 2026
See What’s Really Exposed Across Your IT, OT, IoT, Cloud, and Mobile Assets