
Detected interception of TLS connections with encryption of XMPP (Jabber) instant messaging protocol (Man-in-the-Middle attack) on jabber.ru (also xmpp.ru) service servers hosted by Hetzner and Linode in Germany.
The attacker issued several new TLS certificates using the Let’s Encrypt service, which were used to intercept encrypted STARTTLS connections on port 5222 via a transparent MiTM proxy. The attack was discovered due to the expiration of one of the MiTM certificates, which was not reissued.
No signs of server compromise or spoofing attacks were detected in the network segment; on the contrary, traffic redirection was configured in the network. of the hosting provider.
Source: linux.org.ru
