BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

← Back to the feed

BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

Ars Technica · 5 hours ago

A supply chain attack pushed malware to networks by hijacking IP address space used by Softaculous, the UAE-based maker of the Virtualizor server management platform, to distribute software updates. Unknown attackers exploited weak routing security at hosting provider Hetzner Online, combined with lapses in TLS certificate issuance, to carry out a BGP (Border Gateway Protocol) hijack, allowing them to redirect traffic and serve malicious update packages disguised as legitimate Virtualizor software.

The attack succeeded largely because of a string of avoidable errors: Hetzner's loose routing configuration let hijackers intermittently misdirect traffic over a 33-hour window, and Softaculous had not implemented code signing to verify update authenticity, meaning tampered packages could pass unchecked. Hetzner briefly reclaimed the address space after 12 hours but the attackers repeated the hijack, this time going undetected for almost 10 hours, while Softaculous and downstream peer Zet.net failed to spot the intrusion for 22 hours in total. Softaculous says only a small number of servers were likely affected but cannot confirm which, and has urged all Virtualizor users to check their systems; a BGP security expert described the failures as "silly, preventable mistakes."

  • Attackers hijacked Softaculous's IP space via a BGP routing exploit
  • Malicious updates were pushed to Virtualizor users for over 22 hours undetected
  • Softaculous lacked code signing; Hetzner and partners were slow to react

Software Technology

Read the full article at the source →