BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

by | Sep 16, 2026 | Technology

BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

An unknown group of attackers executed a BGP hijacking operation that compromised infrastructure used to distribute updates for Softaculous, a platform for managing web software and virtual environments. The attackers gained control over IP address space (162.55.80.0/24) assigned to the United Arab Emirates-based company by exploiting multiple security gaps across several organizations.

The attack succeeded through a combination of factors. Hetzner Online, Softaculous’ hosting provider, had configured its routing security in a manner that permitted the hijacking to occur. Additional organizations involved in the attack chain, including Zet.net and Nexon Host, failed to implement proper monitoring systems that would have detected the unauthorized route announcements more quickly. Critically, Softaculous did not employ cryptographic verification for software updates, meaning systems receiving the malicious packages would not have rejected them based on invalid signatures.

The hijacking persisted intermittently across a roughly 33-hour window. The attacker’s initial announcement was active for approximately 12 hours before Hetzner Online reclaimed the address space by announcing the correct routing path. However, when Hetzner subsequently stopped announcing the route, the attacker executed the same hijack a second time, which remained active for nearly 10 hours before being remediated. The organizations involved failed to detect the unauthorized traffic redirection until approximately 22 hours into the incident.

The attack was possible partly because the attacker appended what appeared to be a legitimate origin autonomous system number to the routing announcement, making it compliant with RPKI (Resource Public Key Infrastructure) validation protocols that normally prevent such hijacks. BGP experts characterized the security lapses as preventable errors. Neither Softaculous, Hetzner Online, nor Zet.net provided immediate responses to inquiries regarding the incident. Softaculous subsequently warned that while it believed only a limited number of servers received malicious updates, a definitive victim list could not be established.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI