Karlston Posted December 9, 2020 Share Posted December 9, 2020 FireEye systems taken down in major cyberattack It's likely state-sponsored attackers are to blame (Image credit: Shutterstock) One of the world’s largest cybersecurity firms has been hacked in what it believes to be a state-sponsored attack. US firm FireEye said that company tools used to test cyber defenses had been stolen, with the attackers primarily looking to target government customers. FireEye has confirmed that the attackers targeted and acquired its Red Team assessment tools that are used to test customer security. An investigation into the attacks remains ongoing, with FireEye working alongside the FBI and select partners, including Microsoft. Follow-up attacks As of yet, FireEye has refused to speculate on who the attackers might be but the use of high-level capabilities and a never-before-seen combination of techniques lead them to believe that they have state backing. One of the most worrying aspects of this particular cyberattacks is that it has provided the attackers with a bounty of potential weapons that could be used as part of follow-up attacks. The Red Team tools that were stolen are those that can be hired by companies to carry out mock cyberattacks in order to improve defenses. Although FireEye knows what the tools are and what sort of exploits they can be used to deploy, they will have to act quickly to ensure that safeguards are shared before the cyberattackers make use of their ill-gotten tools. Fortunately, none of the Red Team tools contain zero-day exploits. “Based on my 25 years in cyber security and responding to incidents, I’ve concluded we are witnessing an attack by a nation with top-tier offensive capabilities,” FireEye CEO Kevin Mandia explained. “This attack is different from the tens of thousands of incidents we have responded to throughout the years. The attackers tailored their world-class capabilities specifically to target and attack FireEye. They are highly trained in operational security and executed with discipline and focus. They operated clandestinely, using methods that counter security tools and forensic examination. They used a novel combination of techniques not witnessed by us or our partners in the past.” Via ZDNet FireEye systems taken down in major cyberattack Link to comment Share on other sites More sharing options...
Karlston Posted December 9, 2020 Author Share Posted December 9, 2020 Russia's FireEye Hack Is a Statement—but Not a Catastrophe The fallout from the attack may not be as dire as it first sounds. At least there aren't any zero-days in play.Photograph: David Gray/Reuters/Alamy FireEye has built its reputation on defending high-stakes clients from hackers. Today, the cybersecurity firm acknowledged that it had itself been the victim of a breach—and that the attackers made off with some of its offensive tools. It's a startling admission but almost certainly not as devastating as it may first sound. Like many cybersecurity companies, FireEye uses its “red team” tools to mimic those used in real attacks and look for vulnerabilities in its customers’ digital systems the way real adversaries would. The firm is able to update and refine its methods because it encounters and studies real nation-state and criminal hacking tools while assisting customers with incident response. But that’s still a far cry from investing to develop a novel offensive arsenal—and not nearly as scary as the tools at the disposal of, say, the National Security Agency. FireEye CEO Kevin Mandia said in a blog post today that the company has been dealing with the fallout of “an attack by a nation with top-tier offensive capabilities” and has engaged the help of the Federal Bureau of Investigation along with industry peers like Microsoft. The Washington Post reported on Tuesday that hackers from a group known as APT 29 or Cozy Bear, attributed to Russia’s SVR foreign intelligence service, carried out the breach. FireEye has both global prominence and a history of engaging with Russian actors. The company was the first, for instance, to tie the hacker group known as Sandworm—responsible for blackouts in Ukraine in 2015 and 2016 as well as the hyperdestructive worm NotPetya the following year—to Unit 74455 of Russia’s GRU military intelligence agency. FireEye also provided the first public evidence that the same GRU unit was responsible for the attempted sabotage of the 2018 Winter Olympics. All of those attacks were later named in a US indictment of six Sandworm hackers unsealed in October. The apparently retaliatory hack sends a clear statement that while Russia may have been relatively quiet during the US presidential election, the Kremlin’s digital prowess remains formidable. At the same time, the fallout from the hack doesn’t compare to the release of tools like the NSA’s Eternal Blue tool, which a mysterious group called the Shadow Brokers leaked in 2017, or the breach of exploit broker Hacking Team in 2015. “The most important data that a company like FireEye has is data about its customers. The second most important data they have are the sources and methods they use to protect their customers,” like threat intelligence data, says Richard Bejtlich, former chief security officer of Mandiant, the incident response division of FireEye, and principal security strategist at the network analysis firm Corelight. “Farther down the line are the red team tools, where they’re emulating adversaries.” FireEye said on Tuesday that none of the stolen red team tools utilize so-called zero-day exploits—mechanisms that weaponize secret, unpatched software vulnerabilities, which makes them especially dangerous. Nonetheless, Russia could use the tools itself, share them with others, or leak them publicly. The company said it does not yet fully understand the hackers’ plans or motives, though they primarily focused their attack on information related to some of FireEye’s government clients. Mandia emphasized repeatedly that FireEye is offering more than 300 “countermeasures” meant to make it more difficult for Russia to use the stolen hacking tools effectively. The company has incorporated these digital antidotes, essentially detection mechanisms and blocking tools, into its own security products, has shared them with other firms, and has released them publicly. Making these defenses widely available would make a big difference if Russia were to dump the trove of tools publicly, says Dave Aitel, a former NSA hacker. "Very few teams have detections ready to go if their stuff leaks, so that part of it at least is very impressive,” Aitel says. The stolen tools likely won’t give Russia much it doesn’t already have for its own hacking campaigns, says Jake Williams, a former NSA hacker and founder of the security firm Rendition Infosec. But Williams points out that Russia may feel emboldened to leak the stolen goods publicly, given US Cyber Command’s more aggressive approach recently to naming and shaming actors and their hacking tools. At the end of October, for example, Cyber Command publicly released details about a malware dropper it attributed to Russia’s APT 28, likely for use in attacks on ministries of foreign affairs and other government bodies. Still, in practice the threat from the tools is important but likely not ruinous. “The only reason you should care about this as it stands now is if Russia was part of your threat model already, if they were going to attack you anyway. Then you need to have the detections for these tools ready just in case,” Rendition Infosec’s Williams says. “But if Russia releases the tools publicly, now it's in everyone's threat model. So that's the game changer.” Williams agrees, though, that FireEye’s head start on distributing defense tools makes it more likely that if Russia dumps the tools at all it would be as a sort of victory lap and statement to the US government rather than as a specific effort to wreak havoc. “I’m pretty upset about this,” says Corelight’s Bejtlich, “but it’s not at the level of having a whole bunch of zero-days we’re going to have to deal with.” Additional reporting by Andy Greenberg. Russia's FireEye Hack Is a Statement—but Not a Catastrophe Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.