Attackers were able to substitute elements of the Softaculous infrastructure by injecting a fake route through the BGP protocol, which allowed them to redirect traffic from subnets with Softaculous servers to a server controlled by the attackers. As a result of the attack, they managed to redirect requests to the company's client website, billing, and update distribution servers for Virtualizor software, after which they used them to spread malware and attack the company's clients. The attackers were able to obtain valid TLS certificates for Softaculous domains through Let’s Encrypt, as the automatic domain ownership verification passed through the substituted hosts.
Softaculous provides the namesake platform for automating the installation of web applications, integrated with hosting control panels cPanel, Plesk, DirectAdmin, and ispmanager, and also develops the SitePad website builder, the Webuzo hosting control panel, the Backuply backup system, and the Virtualizor panel for managing virtual servers. During the attack, attackers managed to publish a fake update to the Virtualizor panel containing malicious code. The number of users who installed this update is still unclear.
A fake BGP announcement that changed routing for the subnet 162.55.80.0/24 was sent from the autonomous system AS62390 (NexonHost) via the transit provider AS6204 (Zet.net). The routing disruption lasted for 33 hours, from August 28 23:57 (MSK) to August 30 08:50 (MSK). The probability of a request passing through the server attacker during peak phases of the attack was estimated at 72% (266 out of 368 BGP peers applied the fake route).
Users of Softaculous products, which are typically hosting providers, are advised to check their systems for malware activity and change their access passwords for Softaculous services. Virtualizor administrators are recommended to consider their systems potentially compromised and change API access keys and client keys. One indicator of compromise is the appearance of the file "/etc/systemd/system/java-jre-update.service" in the system. Clients who entered credit card numbers on the softaculous.com/clients website during the attack should check for suspicious transactions.
Domains affected by the attack:
- a.softaculous.com,
- ampps.com,
- api.sitepad.com,
- api.softaculous.com,
- api.virtualizor.com,
- api.webuzo.com,
- backuply.com,
- files.ampps.com,
- files.sitepad.com,
- files.softaculous.com,
- files.virtualizor.com,
- files.webuzo.com,
- pagelayer.com,
- popularfx.com,
- server.softaculous.com,
- sitepad.com,
- softaculous.com, v
- irtualizor.com,
- webuzo.com,
- www.ampps.com,
- www.backuply.com,
- www.popularfx.com,
- www.sitepad.com,
- www.softaculous.com,
- www.virtualizor.com,
- www.webuzo.com.
Source: opennet.ru
