Live data from Hacker News

FireEye Shares Details of Recent Cyber Attack

fireeye.com

21–30 of 251 posts

Re: FireEye Shares Details of Recent Cyber Attack

#23

what does "None of the tools contain zero-day exploits" exactly mean? Does the tools contain knows zero-days but not non public zero days?

Or no exploits at all, ie. post exploitation frameworks, control channels etc. only.

EDIT: Nevermind they added something to the countermeasures repo that goes against that.

Re: FireEye Shares Details of Recent Cyber Attack

#24
post #18

Will there be any public proof or evidence this is a state actor? The blog post has no details and the overuse of adjectives to describe the attacker as extremely competent sounds more like an excuse for their own weaknesses.

Assuming it was a state actor, what type of proof could they release? Presumably the FBI wouldn't want to disclose how it came to this conclusion

Re: FireEye Shares Details of Recent Cyber Attack

#27

https://sec.report/Document/0001370880-20-000037/ I hope to see these tools on Github soon.

I can't imagine Microsoft being especially hospitable to them.

Why not? Everyone else's tools make their way onto Gitzhub eventually.

Re: FireEye Shares Details of Recent Cyber Attack

#29
Huge target on their back no matter what. Like those movies where the tough guy is tested when he gets to prison.

This is where it does not pay to be a public company. If they weren't a public company they wouldn't have to disclose this or acknowledge it and there most likely would not be a credibility damaging story which is easy to find. Sure the story could have gotten out but it would not be easy findable and would not be broadcast widely. An event like this makes major papers and nightly news.

Read that again. There is nothing that says you need to air your dirty laundry. That's not a business or legal principal (other than whatever the public company requirements might be and I am not even 100% certain this was needed but I don't know).

Also as others have pointed out indicating that it was a state sponsored actor is to me (for lack of an elegant way to put it) is 'chicken shit'. Why say that? Why not just say you were attacked and going to try and determine why and make any changes. All it does it sound like an excuse and further to say 'well others are not attacked like this and we can protect against them fine' doesn't fly.

Re: FireEye Shares Details of Recent Cyber Attack

#30
post #20

I wonder if the attackers could use what they stole to impersonate FireEye. As in, some org thinks they're contracted/working with FireEye, but they're actually working with this nation state doing intelligence against the org.

Why impersonate Fireeye even? Just start a legitimate company, gain customers and then use that as a basis to gather what you need. The employees wouldn't know this they'd think they are working for a legitimate company. The bad actors who set it up would just have access to whatever they needed to do what they needed to do. This would take years of work to pull off but could be done.
Post reply on HN