BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

by | Sep 28, 2026 | Technology

BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

An unknown group of attackers successfully executed a supply chain attack that compromised the update infrastructure for Softaculous, a company providing cloud management software used by hosting providers and data centers. The attackers employed BGP hijacking—a technique that redirects internet traffic by manipulating routing announcements—to gain control over IP addresses belonging to Softaculous and used them to distribute malware masquerading as legitimate software updates.

The attack exploited multiple security gaps across several organizations. Hetzner Online, Softaculous’ hosting provider, had insufficiently configured routing security settings that failed to prevent the hijacking. Softaculous itself did not implement code signing for its software updates, meaning users had no cryptographic method to verify whether packages were authentic. Additionally, Softaculous, Hetzner Online, and Zet.net all failed to adequately monitor their systems, allowing the hijacking to persist for approximately 22 hours before detection. The attack occurred in two phases over a 33-hour window, with the attacker successfully re-executing the hijack after Hetzner initially reclaimed the address space.

BGP, the Border Gateway Protocol, forms the foundational routing system that connects independent networks across the internet. The protocol relies on routing announcements that direct traffic between different regions and networks. While security measures like RPKI ROV—which uses cryptographic records to validate routing announcements—exist to prevent hijacking, the attacker exploited Hetzner’s configuration to craft announcements that appeared legitimate under these security protocols. BGP experts described the security lapses as preventable errors that should not have occurred given established best practices.

Softaculous warned that installations of its Virtualizor management platform could have received malicious updates during the incident window, though the company stated it believed only a small number of servers were affected. The company acknowledged that every Virtualizor server should be treated as potentially compromised and recommended users perform security checks. Softaculous and other organizations involved did not immediately respond to inquiries about the incident.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI