Hackers push malicious Virtualizor update in BGP hijacking attack
Summary
Hackers compromised the Virtualizor VPS management software by hijacking its BGP routing infrastructure. This allowed them to redirect update requests to malicious servers, delivering compromised updates to users. The attack exploited the trust in the software's update mechanism to distribute malware.
IFF Assessment
This attack demonstrates a sophisticated method for delivering malware by compromising a trusted software update channel, posing a direct threat to system administrators and their infrastructure.
Defender Context
This incident highlights the critical importance of securing software update infrastructure and the potential for supply chain attacks. Defenders should be vigilant about unexpected update sources and verify the integrity of software updates, especially for infrastructure management tools.