Hijackers compromised network routes used by Softaculous and redirected traffic to servers where they distributed a rogue Virtualizor update to a limited number of installations.
Virtualizor is a web-based control panel made by Softaculous that hosting providers use to set up, manage and sell their virtual private servers (VPS).
According to an urgent security advisory from Softaculous, the attack occurred between 20:57 UTC on 28th August and 06:10 UTC on 30th August.
The hijackers rerouted a block of IP addresses hosted by Hetzner through a Border Gateway Protocol (BGP) hijacking before redirecting traffic to the company’s software update infrastructure and client/billing portal.
BGP hijacking works by having an attacker or misconfigured network publish a false route for a targeted IP address range.
Inadvertently, some networks start routing traffic based on the falsified information, giving bad actors access to data.
Softaculous confirmed that the attack resulted in a rogue Virtualizor update being distributed to a limited number of installations that fetched their updates during the attack. The company noted that the incident affected only a handful of servers and not the wider Virtualizor user-base. (BleepingComputer)
Since the hijacking rerouted requests to the company’s update infrastructure, Softaculous stated that it does not have records of the affected requests.
The company is recommending that Virtualizor administrators check for the suspicious service /etc/systemd/system/java-jre-update.service.
If found, administrators should rotate and lock their API credentials and check their systems for unauthorized SSH keys, users, cronjobs, and outbound connections. Users who accessed the Softaculous client area or provided payment details in the attack window should also change their passwords, check their account activity, and monitor their credit card statements.
Softaculous’ investigation into the incident is ongoing, although the company stated that there is no indication that its other products were affected. The hijacked routing has been restored, and the fraudulent certificate used during the attack has been reported for revocation.
Softaculous released Virtualizor version 3.2.9.9 on 1st September. The update includes a Security Analyzer tool in the administration panel and will roll out cryptographic signing for all software packages. The company will also migrate its infrastructure to a more secure environment. (BleepingComputer)
Read the original article: