MITM attack on JABBER.RU and XMPP.RU
A TLS connection interception was detected with XMPP (Jabber) instant messaging encryption protocol (Man-in-the-Middle attack) on the servers of the jabber.ru service (also xmpp.ru) hosted by Hetzner and Linode in Germany. The attacker issued several new TLS certificates using the Let’s Encrypt service, which were used for intercepting encrypted STARTTLS connections on port 5222 through a transparent MiTM proxy. The attack was discovered in connection with […]
