Technology
Attackers leverage BGP hijacking against Softaculous IP space to push malicious updates
A supply chain attack exploited routing and certificate weaknesses at Hetzner Online to impersonate update infrastructure for Virtualizor and other software.
The short version
- Unidentified attackers hijacked Border Gateway Protocol routing for IP addresses assigned to UAE-based software firm Softaculous.
- The breach compromised infrastructure used to deliver updates and manage services for tools including the Virtualizor virtualization platform.
- The hijacked IP space was used to distribute malware disguised as legitimate software updates to users.
- The full scope of affected networks and the precise identity of the threat actors remain unconfirmed.
Key facts
- Attackers executed a BGP hijacking operation targeting IP addresses belonging to UAE-based software company Softaculous.[Ars Technica]
- The threat actors took advantage of routing security gaps at hosting provider Hetzner Online alongside TLS certificate issuance procedures to gain control of the IP space.[Ars Technica]
- The compromised IP range is normally utilized by Softaculous for customer billing, client portals, and distributing software updates, including those for the Virtualizor management platform.[Ars Technica]
- Control of the hijacked infrastructure enabled the attackers to distribute malware disguised as legitimate updates to users.[Ars Technica]
What remains uncertain
- The identity, location, and affiliation of the attackers have not been publicly identified.[Ars Technica]
- The total number of infrastructure providers, hosting firms, or end devices infected by the malicious updates has not been quantified.[Ars Technica]