BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

by | Sep 6, 2026 | Technology

BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

An unknown group of attackers executed a supply chain attack targeting cloud management software by hijacking internet address space through a combination of routing security vulnerabilities and certificate issuance lapses. The assault specifically targeted Softaculous, a United Arab Emirates-based company that develops platform software for installing web applications and managing virtualized environments. The attackers gained control of IP addresses used by Softaculous to distribute software updates and host client billing systems, then used those addresses to push malware masquerading as legitimate updates to unsuspecting users.

The attack succeeded largely due to misconfigurations at multiple organizations. Hetzner Online, Softaculous’ hosting provider, maintained inadequate routing security settings that proved insufficient to prevent the hijacking. Additionally, Softaculous failed to implement code signing for software updates, a standard security practice that would have allowed client systems to reject the malicious packages. A loose configuration at Hetzner allowed hijackers to misdirect traffic intermittently over two separate periods within a 33-hour window. After Hetzner reclaimed the address space 12 hours into the incident, the attacker executed a second hijacking attempt that took Hetzner approximately 10 hours to remediate.

The incident revealed significant monitoring gaps across multiple parties in the attack chain. Softaculous, Hetzner Online, and Zet.net, which operated as a transit peer, failed to properly monitor their systems and consequently did not detect the ongoing hijacking until 22 hours had elapsed. Questions also arose regarding Nexon Host’s infrastructure, which somehow facilitated the malicious announcement. BGP security experts characterized the lapses as preventable mistakes, noting that the attackers exploited configurations that allowed the hijacking to remain undetected despite existing security protocols.

The attack leveraged vulnerabilities in BGP (Border Gateway Protocol), the fundamental system that routes internet traffic between autonomous networks. While security measures such as RPKI Route Origin Validation exist to prevent such hijackings, the attacker successfully forged an autonomous system path that appeared valid under those protections. Compromised or inadequately secured infrastructure allowed the attackers to inject false routing announcements into the global routing table, directing traffic intended for Softaculous’ legitimate servers to attacker-controlled infrastructure instead.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI