Malicious Virtualizor Update Served via BGP Hijacking
A threat actor used BGP hijacking to redirect traffic intended for Softaculous' legitimate domains, serving malicious updates to virtualization hosting software by spoofing valid TLS certificates. The attack demonstrates how network-layer interception can compromise update mechanisms at scale.
Why this matters
A threat actor used BGP hijacking to redirect traffic intended for Softaculous' legitimate domains, serving malicious updates to virtualization hosting software by spoofing valid TLS certificates. The attack demonstrates how network-layer interception can compromise update mechanisms at scale.
Check the original work
This explanation is Korpalis’s guide to the material, not a replacement for it. Read the publisher’s page for the full method, evidence and limitations.