BGP Hijack Targets Virtualizor Update System, Malicious Patch Delivered to Small User Base

Attack rerouted traffic from Softaculous infrastructure, prompting urgent call for security checks

edit
By LineZotpaper
Published
Read Time2 min
Hackers hijacked BGP routing for Softaculous's update infrastructure between August 28 and 30, delivering a malicious update to a small number of Virtualizor VPS management installations. The vendor has released a new version with a security analyzer and urges administrators to check for signs of compromise.

A sophisticated attack targeting the Virtualizor web control panel leveraged BGP hijacking to redirect update requests to malicious servers. Softaculous, the developer of Virtualizor, disclosed the incident in an urgent notice on September 1, warning administrators that a malicious update package was delivered to a limited number of installations.

The attack occurred between 20:57 UTC on August 28 and 06:10 UTC on August 30, during which the threat actor rerouted a block of IP addresses hosted by Hetzner. By falsely announcing a route to Softaculous's IP addresses, the attacker was able to intercept traffic to the company's software update systems and client/billing portal.

Virtualizor is a legacy control panel used by hosting providers to create, sell, and manage virtual private servers. The compromised delivery occurred only for installations that checked for updates while their traffic was being diverted.

Because requests were redirected to the attacker, Softaculous lacks logs from the incident. The vendor recommends that Virtualizor operators check for the service /etc/systemd/system/java-jre-update.service. If found, administrators should rotate and restrict API credentials, audit systems for unauthorized SSH keys, accounts, scheduled tasks, and outbound connections.

Customers who accessed the Softaculous client area or entered payment information during the incident window are advised to reset passwords, review account activity, and monitor card statements.

Softaculous says routing has been restored, the fraudulent certificate has been reported for revocation, and a new version of Virtualizor (3.2.9.9) was released on September 1 featuring a "Security Analyzer" tool in the admin panel. The company plans to implement cryptographic signing for all software packages and migrate to more secure infrastructure. No indication of impact on other Softaculous products has been found.

§

Analysis

Why This Matters

  • BGP hijacking attacks compromise the trust in software update mechanisms, potentially enabling widespread compromise of hosting infrastructure through a single point of failure.
  • Hosting providers using Virtualizor must immediately check for compromise, as malicious updates could lead to unauthorized access across multiple customer VPS environments.
  • The incident highlights ongoing vulnerabilities in the internet routing infrastructure that can be exploited to bypass software supply chain security.

Background

BGP (Border Gateway Protocol) is the routing protocol that governs how traffic moves across the internet. Hijacking occurs when a network operator falsely claims ownership of IP addresses belonging to another organization. Because BGP relies on trust between autonomous systems, these attacks can be difficult to detect and have been used in recent years to intercept cryptocurrency transactions, redirect traffic to phishing sites, and now deliver malicious software updates. Virtualizor, developed by Softaculous, is widely used in the web hosting industry for managing virtual private servers.

Key Perspectives

Softaculous (vendor): The company has acknowledged the breach, communicated with users, released a patched version, and outlined plans to improve security through cryptographic signing and infrastructure migration. They have confirmed only a small number of installations were affected. Affected hosting providers: Administrators face the immediate burden of checking for signs of compromise, rotating credentials, and auditing systems—a time-sensitive and potentially complex task that could disrupt operations. Cybersecurity critics: Critics argue that BGP hijacking remains an often-overlooked vulnerability, and that companies relying on plain HTTP-based update mechanisms without cryptographic verification are putting users at risk. Skeptics may question whether Softaculous's response—including the scope of the affected user base—is fully transparent.

What to Watch

  • Whether additional compromised installations are identified as Softaculous's investigation continues.
  • Adoption of cryptographic signing for software packages, which the vendor has committed to implementing.
  • Broader industry discussion about BGP security measures, such as RPKI (Resource Public Key Infrastructure) adoption, and whether this incident triggers regulatory attention.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.