Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Orange Spain faces BGP traffic hijacking after RIPE account attacked by malware
    Cyber Security

    Orange Spain faces BGP traffic hijacking after RIPE account attacked by malware

    techempireBy techempire3 Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportJanuary 5, 2024Editorial DepartmentCybersecurity/Malware

    orange spanish'

    On January 3, mobile network operator Orange Spain experienced several hours of network outage after threat actors used administrator credentials obtained through stolen malware to hijack Border Gateway Protocol (BGP) traffic.

    “The IP Network Coordination Center’s (RIPE) Orange account was inappropriately accessed, impacting the browsing of some of our customers,” the company said. explain In a message posted on X (formerly Twitter).

    However, the company stressed that no personal data was compromised and that the incident only affected some browsing services.

    Internet security

    The threat actor’s name on X is Ms_Snow_OwO, claim Get access to your Orange Spain RIPE account. RIPE is a Regional Internet Registration Authority (RIR) that oversees the allocation and registration of IP addresses and Autonomous System (AS) numbers in Europe, Central Asia, Russia and Western Asia.

    “Threat actors used compromised accounts to modify AS numbers belonging to Orange IP addresses, causing Orange to experience significant disruption and a 50% traffic loss,” said cybersecurity firm Hudson Rock.

    BGP traffic shut down
    BGP traffic shut down

    Further analysis revealed that the email address of the administrator account was associated with the computer of an Orange Spain employee who was infiltrated by the Raccoon Stealer malware on September 4, 2023.

    It’s unclear how the thieves gained access to employees’ systems, but this type of malware family is typically spread through malvertising or phishing scams.

    “Among the company credentials identified on the machine, the employee obtained specific credentials for ‘https://access.ripe.net’ using an email address compromised by a threat actor (adminripe-ipnt@orange.es),” the company added road.

    To make matters worse, the password used to protect the Orange RIPE administrator account is “ripeadmin”, which is both weak and predictable.

    Internet security

    Security researcher Kevin Beaumont further pointed out that RIPE neither enforces two-factor authentication (2FA) nor enforces a strong password policy on its accounts, making it vulnerable to abuse.

    “Currently, the infostealer marketplace is selling thousands of credentials to access.ripe.net, which essentially allows you to repeat this scenario across organizations and ISPs across Europe,” Beaumont said.

    RIPE is currently investigating whether any other accounts have been similarly affected and said affected account holders will be contacted directly. It also urges RIPE NCC Access account users to update their passwords and enable multi-factor authentication for their accounts.

    “In the long term, we are accelerating the implementation of 2FA, making it mandatory for all RIPE NCC Access accounts as soon as possible and introducing various verification mechanisms,” Add to.

    This incident highlights the consequences of infection by information stealers and the need for organizations to take steps to protect their networks from known initial attack vectors.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Pokémon Trading Card Website Making 100k!

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    GTA 6 Release Date

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.