Reputation Radar #9: The Layer Below the Address
Threat IntelligenceInfrastructure ReputationSOCWeekly Report

Reputation Radar #9: The Layer Below the Address

Reput.io Team
5 min read

A reputation check answers one question well: is this the right address? Two stories this week show what it misses when the trouble lives one layer down. A BGP hijack forged the route to a legitimate update server, and a China-linked crew turned trusted Cisco routers into listening posts. Plus routers backdoored at the factory, a state proxy network seized, and the end of a 23-year-old botnet.

Most reputation checks answer one question: is this the right address? Is the IP really that IP, is the device on the other end really that device.

Usually that's enough to work with. This week, twice, the answer was a confident yes and it barely helped, because the attack was hiding one layer underneath the address: once in the route to a legitimate server, once in the trusted device itself.

The address was genuine. The route was a forgery.

For about thirty-three hours at the end of August, traffic bound for Virtualizor's update servers quietly went the wrong way.

Virtualizor is the panel a lot of budget hosts use to manage customer VPS, so an update from it gets waved straight through. Here's the detour, per Risky Business: a network called NexonHost announced a small /24 slice of address space that actually belongs to Hetzner. BGP prefers the more specific route, so that narrow announcement beat Hetzner's real one, and the traffic bent toward the attacker.

The clever bit was staying invisible. They kept Hetzner's network number on the path as the apparent origin, so the route still looked like it led home, right down to passing the cryptographic checks meant to catch this. Then: a valid TLS certificate, a clone of the site, and malicious updates for anyone flowing through.

Virtualizor can't even say how many were hit, because the hijacked traffic never touched its own servers to be logged. The address victims resolved was genuinely Virtualizor's. The road to it wasn't.

Your router has an audience now

The second story is about the device, not the path.

Sygnia detailed a long-running Chinese campaign, tracked as Fire Ant (UNC3886), that's been living inside Cisco IOS XR routers and the TACACS servers that hold their admin credentials (The Record). And they aren't just passing through. They watch.

They capture traffic from several points at once, harvest the credentials admins log in with, and time their own commands to blend with the legitimate activity they've been observing. Sygnia's line is the one to keep: control the routers and you don't just gain reach, you gain perspective.

A compromised edge device is a near-perfect vantage point. It sees everything crossing it, nobody watches it the way they watch a laptop, and it makes a quiet jumping-off point into the networks on the far side. The router still routes. It just has an audience now.

What a SOC actually sees

Here's the honest part, and it's the same shape as the update-server story.

We asked our own API about 162.55.80.1, an address inside the exact Hetzner block that got hijacked. It comes back investigate: cloud provider, customer-controlled, hosting legit projects and attacker infrastructure in equal measure, so check what it serves before trusting it.

That verdict is correct. It's also completely blind to the hijack, because reputation describes the address, and the attack was a lie about the route to the address. Different layer, different tool. What catches a BGP hijack is route monitoring and a healthy suspicion of odd, more-specific announcements, not a green checkmark.

The router story lands in the same spot from the other side. If the box doing your routing can become a sensor, it needs the same logging, patching and suspicion you'd give a server. Reputation tells you the device is what it claims to be. It won't tell you who's listening through it.

Also on the radar

  • Some routers arrive backdoored from the factory. VulnCheck took apart an $88 router bought from a US supplier and found two root-level implants baked into 2019 firmware, one of them beaconing to a hardcoded server (The Hacker News). They're cheap white-label Zbtlink boxes that get rebranded and resold, so the same backdoor rides into a lot of networks under a lot of names. The device didn't get compromised. It shipped that way.
  • The FBI seized a state proxy network built from borrowed addresses. Taken down with it was QTRouter, which wove compromised IoT devices, rented VPS and commercial proxies into one relay network for a China-linked group (The Hacker News). The whole point: make state traffic exit through ordinary-looking addresses that rotate faster than a blocklist can keep up.
  • A botnet running since 2003 finally went down. A global operation dismantled Sality by turning its own peer-to-peer trust against it, feeding sinkhole servers into the peer lists infected machines rely on to find each other, until the real operators were edged out (The Hacker News). Twenty-three years is a long run, malware included.

If you want the longer version of why a legitimate address is context and not a verdict, we walked through the cloud version of it in when the phishing page lives on Google's servers.

See you next week.

Sources are linked inline; credit to the original researchers and reporters. If we got a detail wrong, tell us and we'll fix it.

About Reputation Radar: This is written by the small team building Reput.io, not a marketing department. It's our weekly read on the infosec landscape, with a bias toward the thing we care most about: how attackers borrow the reputation of legitimate infrastructure so their traffic looks normal. Every item links the original reporting, and any claim about our own API is run against it live and labelled.

Ready to Try Reput.io?

Start reducing false positives today with our free plan.