BGP hijack rerouted Softaculous updates into malware delivery

A 33-hour BGP hijack diverted Softaculous traffic and pushed a malicious Virtualizor update to a handful of servers.

CSBadmin
2 Min Read

Softaculous is telling customers to reset credentials and inspect their servers after a 33-hour BGP hijack diverted traffic and delivered malware to a handful of installations. The vendor makes web hosting software, including the Virtualizor control panel used to manage virtual private servers.

Starting at 20:57 UTC on August 28, an unrelated network began announcing a block of Hetzner IP addresses used by Softaculous, sending some traffic to an attacker-controlled server. The hijack hit Virtualizor’s software update endpoint plus Softaculous’s client and billing sites. Because the attacker also secured a valid Let’s Encrypt certificate through diverted domain validation, affected connections reached the rogue server without certificate warnings.

The unauthorized route flapped repeatedly across two waves until August 30. Softaculous estimates that during a wave, a given server had roughly a 72 percent chance of sitting on a network that routed the affected range through the attacker.

Worse, a malicious Virtualizor update package reached a “handful” of installations whose update checks passed through the hijack, because update clients did not cryptographically verify packages. The vendor flags /etc/systemd/system/java-jre-update.service as an indicator of compromise and asks operators not to delete it so evidence can be preserved. No malicious packages were found for Backuply, Softaculous, SitePad, or Webuzo.

Anyone who logged into the client area during the window should reset that password, review card statements, rotate API credentials, and audit SSH keys, accounts, and scheduled tasks.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.