There was a significant jump on announcement of this prefix at the time of the event.
stat.ripe.net/widget/bgp-upd… Image
AS7625 announces a /21 that covers the prefix in question (/24). AS9457 also announces a super prefix, but even larger (/16 as oppose to /21). Techinically, it should be fine for either ASNs to originate the prefix in question. But it's a bit stranger for AS9457 to do so. Image
The msgs in question all have link "6461 9457". As @zoaedk originally noticed, the peer link seems not exist. I checked with RouteViews2's RIB dump immediately before this event, and no path exists that contains the link. This smells like #BGP MITM attack by path manipulation.
The only common path segments is "6461 9457". Consider that AS9457 already announces pfxs that covers the hijacked one, there is only one suspect left.

One does not need to originate a prefix to hijack the traffic, one just needs to be on the path.
Play with the relevant raw BGP data from RouteViews and RIPE RIS yourself with this Python notebook. (Powered by alpha version of @bgpkit mrt parser and data broker in Python.)

colab.research.google.com/drive/1juuTgMG… Image
Found 4 affected prefixes:
211.249.221.0/24
121.53.104.0/24
7935:6800::/24
d3f9:dd00::/24

The two v4 pfxs are owned by Kakao Corp (does crypto business) and show very similar pattern of the udpate activity (no history, sudden spike on event). ImageImageImageImage

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Mingwei Zhang 🦀

Mingwei Zhang 🦀 Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(