BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Hackers used the technology of hijacking BGP routing protocols to carry out supply chain attacks on networks using Hetzner Online hosting services and implant malicious software. The attack originated from the hackers exploiting vulnerabilities in the routing security configuration and TLS certificate application process of the service provider, successfully hijacking the IP address range assigned to Softaculous. Softaculous is a Web software installation and management platform developer based in the UAE; the hijacked IP was originally used for releasing updates and hosting customers’ and billing sites. After gaining control, the hackers used these addresses to push malicious software disguised as updates to unsuspecting users.