news.mlab.sh
Back to the feed
threat-intel

33-hour BGP hijack of Softaculous traffic prompts security scramble

High
Summary

A 33-hour BGP hijacking incident diverted traffic intended for Softaculous and Virtualizor, allowing an attacker to deliver a malicious update package to a small number of servers. Customers are urged to reset passwords and review their accounts, while Virtualizor operators are advised to conduct thorough security checks.

A 33-hour BGP hijacking incident disrupted traffic for Softaculous and Virtualizor, leading to a malicious update package being delivered to a limited number of installations. The incident began at approximately 20:57 UTC on August 28, when an unrelated network began announcing a more specific IP address range used by Softaculous, diverting traffic to an attacker-controlled server. This was possible because the attacker announced a more specific IP address range than Hetzner normally advertised, and under standard BGP route selection, this more specific route took precedence.

Softaculous confirmed that the attacker also secured a valid TLS certificate from Let's Encrypt, leveraging the hijacked route for domain ownership validation. This allowed connections to reach the attacker's server without triggering certificate warnings. The unauthorized route was initially accepted by numerous internet vantage points, though it repeatedly flapped before eventually returning.

During the incident, Softaculous estimated that a given server had a 72% chance of being on a network routing traffic through the attacker’s server. Customers are advised to reset their Softaculous client area passwords and review their statements if card details were entered during the period.

More seriously, a malicious Virtualizor update package was delivered to a handful of installations whose update checks passed through the attacker’s server. Softaculous noted that its product update clients did not yet cryptographically verify update packages, so a modified package would not have been rejected on that basis. The vendor has not identified malicious packages targeting Backuply, Softaculous, SitePad, Webuzo, or its other products, although its investigation continues.

Virtualizor operators are advised to rotate and restrict their API credentials, check for unknown SSH keys and accounts, inspect scheduled tasks and outbound connections, and regenerate client-area API keys. Softaculous is also invalidating client-area sessions created during the incident window. The vendor has not identified a definitive list of affected installations, but is advising operators to treat their servers as in scope for checks.

Read the full article at The Register