Key facts
- Hackers conducted a supply-chain attack by hijacking IP addresses used for cloud-management software updates.
- The attackers exploited BGP routing weaknesses and security lapses at Hetzner Online and Softaculous.
- Malware was distributed disguised as legitimate updates for Softaculous's Virtualizor platform.
- The attack involved a BGP hijacking of the 162.55.80.0/24 IP range.
- Failures in code signing and RPKI configuration contributed to the attack's success.
- Multiple entities, including Hetzner Online, Softaculous, Zet.net, and potentially Nexon Host, had security lapses.
Hackers executed a sophisticated supply-chain attack by hijacking a portion of internet routing space to distribute malware disguised as software updates. The attackers exploited weaknesses in the Border Gateway Protocol (BGP) security configurations of hosting provider Hetzner Online and the update process for Softaculous, a company providing software installation and management platforms for hosting providers and data centers.
The operation involved a BGP hijacking that allowed control over IP addresses assigned to Softaculous, specifically the 162.55.80.0/24 range. With this control, the attackers pushed malicious updates that appeared to be legitimate to users of Softaculous's Virtualizor platform. This was possible due to Softaculous's failure to implement code signing for its software updates, meaning modified packages would not be cryptographically rejected.
Lapses in routing security at Hetzner Online, including a loose configuration of RPKI (Resource Public Key Infrastructure) settings, allowed the hijacking to occur intermittently over a 33-hour period. Hetzner Online eventually reclaimed the address space, but the attacker managed to execute the same hijack a second time. Both Hetzner Online and Softaculous, along with transit peer Zet.net, failed to adequately monitor their systems, delaying detection of the ongoing hijacking for approximately 22 hours. Questions also surround Nexon Host, another provider whose infrastructure may have facilitated the malicious BGP announcement.
BGP attacks target the fundamental routing protocols of the internet, exploiting a historical reliance on trust between autonomous systems (ASes). While measures like RPKI with Route Origin Validation (ROV) exist to prevent such hijacks by validating route announcements, the specific configuration and monitoring failures in this incident allowed the attacker to bypass these protections. The attacker's route announcement included a forged origin and a more specific prefix length than typically allowed, which, combined with Hetzner's RPKI settings, enabled the malicious route to propagate.
