FireEye disclosed that a highly sophisticated threat actor breached its internal network and stole the company's custom red-team tools used to test customer defenses. CEO Kevin Mandia said the intruder also sought information related to certain government customers, and the company assessed the operation as state-sponsored activity carried out by an actor with top-tier offensive capabilities; Microsoft helped validate that assessment, and the FBI was notified and joined the investigation.
To reduce the risk of follow-on abuse, FireEye publicly released indicators of compromise and countermeasures to help organizations detect and block any misuse of the stolen tools. The company's rapid disclosure drew attention because FireEye is one of the world's largest cybersecurity firms, and the incident underscored that even major security vendors can be targeted in advanced espionage operations.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
In response to the theft, FireEye released indicators of compromise and countermeasures on GitHub to help organizations detect and defend against potential misuse of the stolen penetration-testing tools.
CEO Kevin Mandia said FireEye assessed the operation as a state-sponsored attack conducted by a nation with top-tier offensive capabilities. Microsoft helped confirm the nation-state assessment, and the FBI was notified and began assisting the investigation.
FireEye disclosed that a highly sophisticated threat actor breached its internal network and stole custom red-team tools used to test customer environments. The company said the intruder also searched for information related to some government customers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
fireeye.com
Open sourceisc.sans.edu
Open sourceunit42.paloaltonetworks.com
Open sourcefireeye.com
Open sourcezdnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.