All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

BGP hijacking used to push malware disguised as software updates

Created at 2 Sep · 11:11 AM1 source↑ Market-relevant
IN SHORT

Hackers exploited BGP routing vulnerabilities and lax security at hosting provider Hetzner Online and software provider Softaculous to hijack IP addresses. They used these hijacked addresses to distribute malware disguised as legitimate software updates to unsuspecting users.

Key Numbers

33-hourtotal window of hijacking activity
22 hoursduration before detection by multiple parties
12 hourstime for Hetzner to reclaim address space initially
10 hourstime for Hetzner to react to second hijack
256IP addresses in the hijacked /24 block
3.7 billionpublicly available IPv4 addresses

Who's Involved

Hetzner Online
Hosting provider whose routing security was exploited
Softaculous
Software provider whose IP space was hijacked and used to distribute malware
Zet.net
Transit peer downstream from Hetzner Online that failed to monitor systems
Nexon Host
Host provider that may have facilitated the malicious announcement
Ben Cartwright-Cox
BGP expert who called the lapses 'silly, preventable mistakes'
Doug Madory
BGP expert who detailed the attack's technical execution and RPKI bypass
BGP hijacking used to push malware disguised as software updates

↳ Why This Matters

This incident highlights critical vulnerabilities in internet routing security and software supply chains, demonstrating how attackers can leverage BGP hijacks and lax update validation to compromise production networks and distribute malware, impacting critical infrastructure providers and their customers.

Key facts

  • Hackers conducted a supply-chain attack by hijacking IP addresses used for cloud-management software updates.
  • The attackers exploited BGP routing weaknesses and security lapses at Hetzner Online and Softaculous.
  • Malware was distributed disguised as legitimate updates for Softaculous's Virtualizor platform.
  • The attack involved a BGP hijacking of the 162.55.80.0/24 IP range.
  • Failures in code signing and RPKI configuration contributed to the attack's success.
  • Multiple entities, including Hetzner Online, Softaculous, Zet.net, and potentially Nexon Host, had security lapses.

Hackers executed a sophisticated supply-chain attack by hijacking a portion of internet routing space to distribute malware disguised as software updates. The attackers exploited weaknesses in the Border Gateway Protocol (BGP) security configurations of hosting provider Hetzner Online and the update process for Softaculous, a company providing software installation and management platforms for hosting providers and data centers.

The operation involved a BGP hijacking that allowed control over IP addresses assigned to Softaculous, specifically the 162.55.80.0/24 range. With this control, the attackers pushed malicious updates that appeared to be legitimate to users of Softaculous's Virtualizor platform. This was possible due to Softaculous's failure to implement code signing for its software updates, meaning modified packages would not be cryptographically rejected.

Lapses in routing security at Hetzner Online, including a loose configuration of RPKI (Resource Public Key Infrastructure) settings, allowed the hijacking to occur intermittently over a 33-hour period. Hetzner Online eventually reclaimed the address space, but the attacker managed to execute the same hijack a second time. Both Hetzner Online and Softaculous, along with transit peer Zet.net, failed to adequately monitor their systems, delaying detection of the ongoing hijacking for approximately 22 hours. Questions also surround Nexon Host, another provider whose infrastructure may have facilitated the malicious BGP announcement.

BGP attacks target the fundamental routing protocols of the internet, exploiting a historical reliance on trust between autonomous systems (ASes). While measures like RPKI with Route Origin Validation (ROV) exist to prevent such hijacks by validating route announcements, the specific configuration and monitoring failures in this incident allowed the attacker to bypass these protections. The attacker's route announcement included a forged origin and a more specific prefix length than typically allowed, which, combined with Hetzner's RPKI settings, enabled the malicious route to propagate.

Frequently asked questions

A BGP hijacking occurs when an attacker falsely announces control over IP address ranges they do not own, redirecting internet traffic through their own networks.

Softaculous is a UAE-based company that provides a platform for installing and managing web software. Virtualizor is its management platform for virtualized environments.

RPKI (Resource Public Key Infrastructure) with ROV (Route Origin Validation) is a security framework that uses cryptographic records (ROAs) to validate BGP route announcements, helping to prevent hijacks.

The attackers forged the AS path in their BGP announcement and exploited Hetzner Online's RPKI configuration, which allowed smaller sub-prefixes to be considered valid, thus bypassing standard validation checks.

What Happens Next

01Softaculous is advising users to treat every Virtualizor server as in scope for checks.
02Further investigation into the exact methods used by the attackers and the extent of the compromise is ongoing.

How It Developed

Hackers performed a BGP hijacking to gain control of IP addresses assigned to Softaculous.
The attackers used the hijacked IP space to push malware masquerading as software updates.
Lax routing security configuration at Hetzner Online and Softaculous's failure to validate software updates contributed to the attack's success.
Hetzner Online reclaimed the address space, but the attacker executed the same hijack a second time.
Softaculous, Hetzner Online, and Zet.net failed to properly monitor their systems and detect the hijacking until it had been ongoing for 22 hours.
The attack likely originated with Nexon Host, possibly through a compromise of its infrastructure or a customer exploiting security gaps.
The attacker appended Hetzner Online's ASN to the BGP path, making the route appear RPKI-valid and bypass security measures.
Hetzner Online's RPKI configuration allowed sub-prefixes as small as /24 to be considered valid, enabling the bypass.

Sources

T1
Well-executed BGP hijattack uses hijacked IPs to infect real networksvar abtest_2170130 = new ABTest(2170130, 'impression');Ars Technica

Related Stories

AI models show promise in detecting heat shield anomalies
1 Sep · 2:51 PM
Russia's Starlink rival Rassvet faces launch setbacks
2 Sep · 11:26 AM
Dropbox Accounts Breached Via Lenovo ID Authentication Flaw
1 Sep · 8:07 PM
Fake Claude desktop app distributes crypto-stealing malware
1 Sep · 2:06 PM
X reports user account targeting attempts post-X Money launch
1 Sep · 9:16 PM