33-hour BGP hijack of Softaculous traffic prompts security scramble

← Back to the feed

33-hour BGP hijack of Softaculous traffic prompts security scramble

The Register · 2 hours ago

Hosting software vendor Softaculous has told customers of its Softaculous and Virtualizor products to reset their credentials and check their servers for malware following a 33-hour BGP hijacking attack that redirected traffic to systems operated by an attacker. The incident, which began on 28 August, saw an unrelated network announce a more specific version of a Hetzner IP address block used by Softaculous, causing internet routers worldwide to send traffic intended for the vendor's update, client and billing systems to the attacker instead. This matters because it allowed the attacker to obtain a legitimate TLS certificate via Let's Encrypt and, in some cases, push a malicious update package to Virtualizor installations without triggering the usual browser security warnings.

The hijack ran in two waves, from around 20:57 UTC on 28 August until it was fully withdrawn between 05:50 and 06:10 UTC on 30 August, with Hetzner briefly reclaiming the route for about 11 hours in between after Softaculous alerted it. Softaculous estimates any given server had roughly a 72% chance of routing through the attacker while the hijack was live, based on data from RIPE routing collectors. It has confirmed a malicious Virtualizor update reached "a handful" of installations, exploiting the fact its update client did not yet cryptographically verify packages, and is advising all Virtualizor operators to check for a suspicious systemd service file rather than assume compromise. Customers who logged in or entered payment details during the affected window have been told to change passwords and monitor their statements.

  • BGP hijack redirected Softaculous/Virtualizor traffic for 33 hours from 28-30 August.
  • Attacker got a valid TLS cert and pushed malware to some Virtualizor servers.
  • Customers urged to reset passwords, check card statements and inspect servers.

New here? Start with this

Softaculous makes widely used software that hosting companies rely on to install and manage websites and servers, including a tool called Virtualizor that controls virtual server setups. Because so many web hosts depend on it, any problem with Softaculous's systems has the potential to affect a large number of servers around the world at once.

The attack involved something called BGP hijacking, a technique that exploits how internet traffic finds its way from one point to another. The internet's routing system relies on networks announcing which addresses they handle, and this is based on trust rather than strong verification, so a network can, deliberately or by mistake, claim to handle addresses that belong to someone else. When that happens, traffic meant for the real destination can end up being sent to the network making the false claim instead.

This matters because Softaculous's update and billing systems are used to deliver software and handle customer logins and payments, so anyone able to intercept that traffic could potentially pose as the real service, collect sensitive information, or interfere with the software being sent out. BGP hijacks are a recognised weakness in how the internet works, and incidents like this are being examined closely because of the wider disruption or fraud they could enable.

Americas Software Technology World

Read the full article at the source →