HeadlinesBriefing favicon HeadlinesBriefing.com

BGP Hijack Softaculous Malware Attack Routing Security

Ars Technica •
×

Hackers executed a supply chain attack by hijacking Internet routing space used for cloud management software updates. Exploiting routing security weaknesses at Hetzner Online and TLS certificate processes, attackers gained control of IP addresses assigned to Softaculous, a UAE-based company behind Virtualizor. With control of these IPs, the threat actors pushed malware disguised as legitimate updates to unsuspecting users.

Softaculous confirmed that their update clients did not cryptographically verify packages, allowing the malicious updates to be accepted. A loose configuration by Hetzner Online allowed hijackers to intermittently misdirect traffic over two IP spans within a 33-hour window. Hetzner reclaimed the space 12 hours after the initial hijack, only for the attacker to execute a second hijack, which took nearly 10 hours to stop.

Downstream transit peer Zet.net and Softaculous itself failed to monitor their systems, missing the attack for 22 hours. BGP expert Ben Cartwright-Cox called the lapses silly, preventable mistakes. The incident highlights critical failures in routing security and update validation across multiple networks.