Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label file server attacks. Show all posts

Hackers Hijack BGP Routes to Deliver Malicious Virtualizor Update

 

Hijackers compromised network routes used by Softaculous and redirected traffic to servers where they distributed a rogue Virtualizor update to a limited number of installations. Virtualizor is a web-based control panel made by Softaculous that hosting providers use to set up, manage and sell their virtual private servers (VPS). 

According to an urgent security advisory from Softaculous, the attack occurred between 20:57 UTC on 28th August and 06:10 UTC on 30th August. The hijackers rerouted a block of IP addresses hosted by Hetzner through a Border Gateway Protocol (BGP) hijacking before redirecting traffic to the company’s software update infrastructure and client/billing portal. BGP hijacking works by having an attacker or misconfigured network publish a false route for a targeted IP address range. 

Inadvertently, some networks start routing traffic based on the falsified information, giving bad actors access to data. Softaculous confirmed that the attack resulted in a rogue Virtualizor update being distributed to a limited number of installations that fetched their updates during the attack. The company noted that the incident affected only a handful of servers and not the wider Virtualizor user-base. (BleepingComputer) Since the hijacking rerouted requests to the company’s update infrastructure, Softaculous stated that it does not have records of the affected requests. 

The company is recommending that Virtualizor administrators check for the suspicious service /etc/systemd/system/java-jre-update.service. If found, administrators should rotate and lock their API credentials and check their systems for unauthorized SSH keys, users, cronjobs, and outbound connections. Users who accessed the Softaculous client area or provided payment details in the attack window should also change their passwords, check their account activity, and monitor their credit card statements. 

Softaculous’ investigation into the incident is ongoing, although the company stated that there is no indication that its other products were affected. The hijacked routing has been restored, and the fraudulent certificate used during the attack has been reported for revocation. Softaculous released Virtualizor version 3.2.9.9 on 1st September. The update includes a Security Analyzer tool in the administration panel and will roll out cryptographic signing for all software packages. The company will also migrate its infrastructure to a more secure environment. (BleepingComputer)

Clop Ransomware Targets Internet-Facing Gladinet CentreStack Servers in New Data Theft Campaign

 

The Clop ransomware group, also known as Cl0p, has launched a new extortion campaign aimed at Gladinet CentreStack file servers that are exposed to the internet.

Gladinet CentreStack is a file-sharing solution that allows organizations to securely access and share files stored on on-premises servers through web browsers, mobile applications, and mapped drives—without the need for a VPN. According to Gladinet, CentreStack “is used by thousands of businesses from over 49 countries.”

Since April, Gladinet has issued multiple security patches to fix several vulnerabilities that were actively exploited in attacks, including some zero-day flaws.

Threat actors linked to the Clop cybercrime operation are now actively scanning for CentreStack servers accessible online and breaching vulnerable systems. Curated Intelligence confirmed to BleepingComputer that attackers are leaving ransom notes on compromised servers.

At present, the exact vulnerability being used in these intrusions remains unknown. It is unclear whether Clop is exploiting a previously undisclosed zero-day flaw or taking advantage of an older vulnerability that has not yet been patched by affected organizations.

“Incident Responders from the Curated Intelligence community have encountered a new CLOP extortion campaign targeting Internet-facing CentreStack file servers,” warned threat intel group Curated Intelligence on Thursday.

“From recent port scan data, there appears to be at least 200+ unique IPs running the "CentreStack - Login" HTTP Title, making them potential targets of CLOP who is exploiting an unknown CVE (n-day or zero-day) in these systems.”

Clop has repeatedly targeted secure file transfer and file-sharing platforms as part of its extortion operations. The group has previously been responsible for high-profile breaches involving Accellion FTA, GoAnywhere MFT, Cleo, and MOVEit Transfer servers. The MOVEit campaign alone impacted more than 2,770 organizations globally.

More recently, Clop exploited an Oracle E-Business Suite zero-day vulnerability, tracked as CVE-2025-61882, to steal sensitive data from numerous organizations beginning in early August 2025.

Affected Oracle customers reportedly include Harvard University, The Washington Post, GlobalLogic, the University of Pennsylvania, Logitech, and Envoy Air, a subsidiary of American Airlines.

Following successful intrusions, the group exfiltrates confidential data and publishes it on its dark web leak site, often distributing the stolen files via Torrent downloads.

The U.S. Department of State has announced a reward of up to $10 million for information that could help attribute Clop’s cybercrime activities to a foreign government.

A spokesperson for Gladinet was not immediately available to comment when contacted by BleepingComputer earlier today.