Hackers push malicious Virtualizor update in BGP hijacking attack

A Sophisticated Cyberattack Targets Virtualizor VPS Management Software

A highly coordinated cyberattack has targeted the Virtualizor virtual private server (VPS) management software, leaving a small number of users vulnerable to potential security breaches. The attackers exploited a Border Gateway Protocol (BGP) hijacking attack to redirect update requests for Virtualizor to malicious servers, allowing them to deliver a tainted software update to unsuspecting administrators.

For the uninitiated, BGP is a fundamental protocol that helps route internet traffic between networks. However, when an attacker intercepts and manipulates this process, they can reroute legitimate traffic to malicious destinations, where it can be compromised or hijacked for their own gain. In this case, the attackers exploited a rare but serious vulnerability in the way Virtualizor’s update infrastructure was configured.

According to Softaculous, the vendor behind Virtualizor, the attack occurred between August 28th and August 30th, during which time an attacker successfully rerouted a block of IP addresses hosted by Hetzner. This allowed them to intercept software updates and redirect them to their own servers, where they could inject malicious code into the Virtualizor package. While only a small number of installations were affected, Softaculous warns that users who accessed the client area or entered payment information during this period should take immediate action to protect themselves.

In particular, administrators are advised to check for and remove any suspicious service configurations, including the `java-jre-update.service` file located at `/etc/systemd/system/`. They should also rotate and restrict API credentials, audit systems for unauthorized SSH keys, accounts, scheduled tasks, and outbound connections. Furthermore, users who accessed the Softaculous client area or entered payment information during the attack window are urged to reset their passwords, review account activity, and monitor card statements for any suspicious activity.

While the investigation into this incident is ongoing, Softaculous has already taken steps to mitigate the damage. They have restored routing, revoked the fraudulent certificate, and released a new version of Virtualizor (3.2.9.9) with additional security features. Going forward, they plan to implement cryptographic signing for all software packages and migrate to more robust infrastructure.

As this attack highlights, even seemingly innocuous software updates can be compromised by sophisticated attackers. To stay safe, administrators should remain vigilant and take proactive steps to protect their systems from the inside out. By monitoring system activity, rotating credentials regularly, and staying up-to-date with security patches and updates, users can significantly reduce their risk of falling victim to such attacks.

In conclusion, this incident serves as a stark reminder that cyberattacks can strike even the most secure systems. As we continue to navigate an increasingly complex threat landscape, it’s essential for administrators to remain vigilant and prioritize proactive security measures to safeguard against potential breaches.


Source: Bleeping Computer — 2026-09-01