← Latest briefing

Technology

Attackers leverage BGP hijacking against Softaculous IP space to push malicious updates

A supply chain attack exploited routing and certificate weaknesses at Hetzner Online to impersonate update infrastructure for Virtualizor and other software.

The short version

  • Unidentified attackers hijacked Border Gateway Protocol routing for IP addresses assigned to UAE-based software firm Softaculous.
  • The breach compromised infrastructure used to deliver updates and manage services for tools including the Virtualizor virtualization platform.
  • The hijacked IP space was used to distribute malware disguised as legitimate software updates to users.
  • The full scope of affected networks and the precise identity of the threat actors remain unconfirmed.

Key facts

  • Attackers executed a BGP hijacking operation targeting IP addresses belonging to UAE-based software company Softaculous.[Ars Technica]
  • The threat actors took advantage of routing security gaps at hosting provider Hetzner Online alongside TLS certificate issuance procedures to gain control of the IP space.[Ars Technica]
  • The compromised IP range is normally utilized by Softaculous for customer billing, client portals, and distributing software updates, including those for the Virtualizor management platform.[Ars Technica]
  • Control of the hijacked infrastructure enabled the attackers to distribute malware disguised as legitimate updates to users.[Ars Technica]

What remains uncertain

  • The identity, location, and affiliation of the attackers have not been publicly identified.[Ars Technica]
  • The total number of infrastructure providers, hosting firms, or end devices infected by the malicious updates has not been quantified.[Ars Technica]

Sources