BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Summary
Hackers carried out an attack by taking over part of the Internet address space used by Softaculous, a company that provides software updates for web hosting management tools. The attackers tricked users into installing malware by sending fake update files during the time they controlled this Internet space. The attack happened because of weak security setups and several mistakes by Softaculous, Hetzner Online (the hosting provider), and others involved.Key Facts
- The attack used a method called BGP hijacking, which takes control of Internet routing paths to redirect traffic.
- Softaculous provides platforms like Virtualizor for managing web software and virtual servers.
- Attackers exploited weak routing security at Hetzner Online, Softaculous’ hosting provider, to control IP addresses.
- The hijackers pushed malware pretending to be official software updates to users.
- Softaculous did not use code signing to verify update files, which allowed fake updates to install.
- Hetzner Online first reclaimed the hijacked Internet space after 12 hours but lost control again, with the second hijack lasting almost 10 hours.
- The attack was ongoing intermittently for about 33 hours before detection.
- Other companies involved, including Zet.net and Nexon Host, also failed to detect or prevent the hijacking.
This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.