On 03/09/2026 12:59, James Bensley wrote: My question is what was the purpose? Obviously, the attacker invested lots of time and effort on setting this up, but "why"? What server in the range https://ipinfo.io/ips/162.55.80.0/24 was the target and what was stolen? softaculous.com? "served a backdoored update to installations that happened to check during the window". No monetary benefit so far. Perhaps some server that updated during the hijack period? But that would be hit or miss - again where is the monetary benefit? I am missing something. Regards, Hank
There is a nice write-up here: https://bgpkit.com/blog/virtualizor-bgp- hijack-anatomy/ <https://bgpkit.com/blog/virtualizor-bgp-hijack-anatomy/>
For me, the real question is why did the transit provider accept a the hijacked prefix from someone that's not upstream of the victim?
Does anyone know if the transit provider has been asked comments?
With kind regards, James Bensley (he/him) ------------------------------------------------------------------------