
Attackers successfully executed a supply chain attack by hijacking internet address space assigned to Softaculous, a United Arab Emirates-based software company that develops platform installation tools and virtualization management systems used by hosting providers and data centers. The attack leveraged multiple security failures to redirect customer traffic and distribute malicious software updates.
The hijacking exploited weak routing security configuration at Hetzner Online, Softaculous’ hosting provider, alongside lapses in how valid TLS certificates were issued. Attackers gained control of IP addresses in the 162.55.80.0/24 range that Softaculous used to distribute software updates and host client and billing services. With this control, the threat actors pushed malware disguised as legitimate updates to unsuspecting users across multiple networks.
A critical vulnerability in Softaculous’ development practices compounded the problem: the company failed to implement code signing verification for software updates, a standard security practice. This meant that modified update packages would not be rejected by client systems even after the hijacking was detected. According to Softaculous’ disclosure, while the company believed only a small number of servers were actually compromised, a definitive list could not be produced.
The attack unfolded across multiple error windows spanning approximately 33 hours. After Hetzner Online initially reclaimed the hijacked address space 12 hours into the attack, the company stopped announcing the correct routing path, enabling the attacker to execute the same hijack a second time. This second attempt remained active for nearly 10 hours before Hetzner responded. Softaculous, Hetzner Online, and downstream transit provider Zet.net all failed to detect the ongoing hijacking for approximately 22 hours, pointing to inadequate monitoring infrastructure.
The incident highlights fundamental weaknesses in how routing security measures were configured. While RPKI ROV protocols exist to prevent such hijacks through cryptographic validation, Hetzner’s configuration settings allowed the attack to remain valid under these security systems. Security experts characterized the combination of failures as preventable mistakes rooted in weak routing configuration, insufficient monitoring, and missing standard security practices rather than sophisticated attacks exploiting unknown vulnerabilities.
Article Attribution | Read More at Article Source
Article summary produced by Claude AI