BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

by | Sep 2, 2026 | Technology

BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

An unidentified group of attackers successfully executed a supply chain attack by hijacking Internet address space used by Softaculous, a software installation and management platform. The attackers exploited multiple security lapses to redirect traffic and distribute malware disguised as legitimate software updates to users of Virtualizor, Softaculous’ virtualized environment management product.

The attack leveraged weak routing security configurations at Hetzner Online, the hosting provider managing Softaculous’ IP address space. The attacker announced a more specific IP prefix (162.55.80.0/24) containing 256 addresses that hosted Softaculous’ update endpoints and client services. The hijacking occurred intermittently over a 33-hour window, with attackers successfully misdirecting traffic twice before Hetzner Online regained control of the address space. The company took 12 hours to respond to the first hijacking and nearly 10 hours to address the second occurrence.

Multiple organizations failed to implement standard security practices that could have prevented the attack. Softaculous did not employ code signing to cryptographically verify software updates, meaning recipients had no way to detect tampering. Additionally, Softaculous, Hetzner Online, and downstream transit peer Zet.net failed to properly monitor their systems for suspicious routing activity, allowing the hijacking to continue undetected for 22 hours. Questions also emerged regarding how Nexon Host’s infrastructure facilitated the malicious announcements.

BGP experts characterized the security failures as preventable errors. While internet architects have developed safeguards like RPKI Route Origin Validation to prevent hijacking, Hetzner’s configuration allowed attackers to work around these protections by appending the legitimate AS number to their forged announcements. The incident underscores persistent vulnerabilities in the foundational protocols that connect the global internet, despite decades of known attack vectors targeting BGP routing security.

Article Attribution | Read More at Article Source

Article summary produced by Claude AI