Latest BGP hijack targets hosting software vendor
RPKI-valid BGP hijack plus fraudulent TLS certificate delivered a malicious Virtualizor update to Softaculous customers, APNIC analysis shows.
Attackers announced a more-specific 162.55.80.0/24 covering Softaculous's update endpoint, apparently via NexonHost (AS62390), with a forged AS24940 origin that passed RPKI validation and beat Hetzner's legitimate 162.55.0.0/16 route. Using the hijack, they obtained a technically valid TLS certificate by controlling the CA validation quorum, then served a malicious Virtualizor update to a small number of installations. Hetzner countered by announcing the /24, and the incident mirrors the 2022 KLAYswap and Celer Bridge BGP-PKI attacks.
65