Attackers used BGP to substitute the Virtualizor update server and the Softaculous website
Attackers were able to substitute elements of the Softaculous company's infrastructure by injecting a fake route through the BGP protocol, which allowed them to redirect traffic from the subnet with Softaculous servers to a server controlled by the attackers. As a result of the attack, among other things, they were able to redirect requests to the company's customer website, billing, and update distribution servers for Virtualizor software, after which they used them to distribute malware […]
