A sophisticated attack targeting the Virtualizor web control panel leveraged BGP hijacking to redirect update requests to malicious servers. Softaculous, the developer of Virtualizor, disclosed the incident in an urgent notice on September 1, warning administrators that a malicious update package was delivered to a limited number of installations.
The attack occurred between 20:57 UTC on August 28 and 06:10 UTC on August 30, during which the threat actor rerouted a block of IP addresses hosted by Hetzner. By falsely announcing a route to Softaculous's IP addresses, the attacker was able to intercept traffic to the company's software update systems and client/billing portal.
Virtualizor is a legacy control panel used by hosting providers to create, sell, and manage virtual private servers. The compromised delivery occurred only for installations that checked for updates while their traffic was being diverted.
Because requests were redirected to the attacker, Softaculous lacks logs from the incident. The vendor recommends that Virtualizor operators check for the service /etc/systemd/system/java-jre-update.service. If found, administrators should rotate and restrict API credentials, audit systems for unauthorized SSH keys, accounts, scheduled tasks, and outbound connections.
Customers who accessed the Softaculous client area or entered payment information during the incident window are advised to reset passwords, review account activity, and monitor card statements.
Softaculous says routing has been restored, the fraudulent certificate has been reported for revocation, and a new version of Virtualizor (3.2.9.9) was released on September 1 featuring a "Security Analyzer" tool in the admin panel. The company plans to implement cryptographic signing for all software packages and migrate to more secure infrastructure. No indication of impact on other Softaculous products has been found.