Interestana
Home/News/BGP Hijack Attack Leveraged Software Update Process
Ars Technica2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

BGP Hijack Attack Leveraged Software Update Process

BGP Hijack Attack Leveraged Software Update Process

Hackers executed a sophisticated supply chain attack by hijacking a segment of internet space used for updating cloud management software. This unusual technique targeted hosting providers, data centers, and other large infrastructure companies that rely on this software for their operations. The attackers exploited weaknesses in the routing security setup of hosting provider Hetzner Online and the process for obtaining valid TLS certificates, according to a detailed analysis of the incident. These combined vulnerabilities allowed the attackers to successfully perform a Border Gateway Protocol (BGP) hijacking. BGP is the fundamental routing protocol of the internet, responsible for directing traffic between different networks. By hijacking BGP, the attackers gained control over IP addresses that were legitimately assigned to Softaculous, a company based in the United Arab Emirates. Softaculous is known for its platform that facilitates the installation and management of web software, and it also develops Virtualizor, a management platform specifically designed for virtualized environments. The compromised IP addresses were being used by Softaculous to issue software updates and to host its client and billing websites. Once the attackers gained control over this hijacked internet space, they began distributing malware. This malware was disguised as legitimate software updates, making it highly likely that unsuspecting users would download and install it. This method of distribution is particularly effective because it leverages the trust users place in the update mechanisms of the software they regularly use. The attack highlights significant security lapses in the internet's routing infrastructure and the processes for verifying software authenticity. The exploitation of both BGP and TLS certificate acquisition demonstrates a multi-pronged approach by the attackers to achieve their objective. Hetzner Online, a significant hosting provider, was directly implicated in the routing security weaknesses that were exploited. The method used to obtain TLS certificates also presented a vulnerability that the attackers were able to leverage. The success of this attack underscores the ongoing challenges in securing the global internet infrastructure against increasingly sophisticated threats. The reliance on centralized update mechanisms, while convenient, also presents a single point of failure that can be exploited by malicious actors. The investigation into the full scope of the attack and the extent of the compromise is ongoing, with a focus on understanding how these specific vulnerabilities were identified and exploited. The incident serves as a critical reminder for organizations to continuously review and strengthen their network security protocols, particularly those related to BGP security and certificate management, to prevent similar breaches in the future. The attackers remain unknown, and their motives are still under investigation, but the impact on the affected networks and their users is significant.

Original source — read the full reporting at the publisher:

Read on Ars Technica

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next