Presumably ransomware or similar attacks into infrastructure, I would assume those who ingested the false update have not fully seen the impact of this yet But yeah, the general customer base of virtualizor suggests some smaller VPS hosts and their customer are on their way to a bad time On Thu, 3 Sept 2026 at 14:11, Hank Nussbacher <hank@interall.co.il> wrote:
On 03/09/2026 12:59, James Bensley wrote:
My question is what was the purpose? Obviously, the attacker invested lots of time and effort on setting this up, but "why"? What server in the range https://ipinfo.io/ips/162.55.80.0/24 was the target and what was stolen? softaculous.com? "served a backdoored update to installations that happened to check during the window". No monetary benefit so far. Perhaps some server that updated during the hijack period? But that would be hit or miss - again where is the monetary benefit?
I am missing something.
Regards, Hank
There is a nice write-up here: https://bgpkit.com/blog/virtualizor-bgp- hijack-anatomy/ <https://bgpkit.com/blog/virtualizor-bgp-hijack-anatomy/>
For me, the real question is why did the transit provider accept a the hijacked prefix from someone that's not upstream of the victim?
Does anyone know if the transit provider has been asked comments?
With kind regards, James Bensley (he/him) ------------------------------------------------------------------------
To unsubscribe from this mailing list or change your subscription options, please visit: https://mailman.ripe.net/mailman3/lists/routing-wg.ripe.net/ As we have migrated to Mailman 3, you will need to create an account with the email matching your subscription before you can change your settings. More details at: https://www.ripe.net/membership/mail/mailman-3-migration/