Home / Technology / Hackers Hijack Internet Space for Malware Updates

Hackers Hijack Internet Space for Malware Updates

Summary

  • Attackers used BGP hijacking to control Softaculous IP addresses.
  • Malware was disguised as software updates to infected servers.
  • Preventable security lapses enabled the supply-chain attack.
Hackers Hijack Internet Space for Malware Updates

Hackers recently conducted a sophisticated supply-chain attack, compromising networks through an unusual method: hijacking internet space essential for updating cloud-management software. This technique targeted infrastructure companies, data centers, and hosting providers.

The attackers exploited weaknesses in the routing security setup of Hetzner Online and the process for obtaining valid TLS certificates. These lapses allowed them to perform a BGP hijacking, gaining control over IP addresses associated with Softaculous, a company that provides software installation and management platforms.

With control of the hijacked IP space, the attackers pushed malware disguised as legitimate software updates. Softaculous warned that its update clients did not cryptographically verify these packages, potentially allowing malicious updates onto a small number of affected servers.

Experts identified lax routing security configurations by Hetzner Online and Softaculous's failure to validate software updates as key contributors to the attack's success. These were described as "silly, preventable mistakes."

BGP attacks exploit the foundational routing protocols of the internet. While measures like RPKI have been developed to prevent such hijackings, this incident highlights how misconfigurations can allow them to succeed. The attack pulsed on and off over a 33-hour window, with responses from involved parties taking hours.

Disclaimer: This story has been auto-aggregated and auto-summarised by a computer program. This story has not been edited or created by the Feedzop team.

Read more news on

Property Code: 5571