Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical Vulnerability in Popular npm Package Exposes Users to Supply Chain Attacks
September 1, 2026
Malicious iPhone Website Themes Steal Crypto Wallet Seeds
September 1, 2026
Cisco Routers Vulnerable to State-Sponsored Attacks, Critical Infrastructure at Risk
September 1, 2026
Home/CyberSecurity News/BGP Hijack Diverts Softaculous Traffic, Delivers Malicious Virtualizor Update
CyberSecurity News

BGP Hijack Diverts Softaculous Traffic, Delivers Malicious Virtualizor Update

Key Takeaways A BGP hijack targeting Softaculous traffic diverted update requests for Virtualizor. Malicious Virtualizor updates, capable of executing code as root, were delivered to a limited number...

David kimber
David kimber
September 1, 2026 4 Min Read
4 0

Key Takeaways

  • A BGP hijack targeting Softaculous traffic diverted update requests for Virtualizor.
  • Malicious Virtualizor updates, capable of executing code as root, were delivered to a limited number of hypervisor servers.
  • The incident, which ran from August 28 to August 30, 2026, compromised hosting infrastructure, not just individual websites.
  • Affected systems are identifiable by a specific systemd service file; immediate action and vendor contact are advised.
  • Passwords and API keys used during the compromise window should be reset.

A sophisticated BGP hijacking operation last week redirected traffic intended for Softaculous, leading to the distribution of a malicious Virtualizor update to an undisclosed number of hypervisor servers. This incident, detailed in an incident report from the vendor, represents a significant compromise within the hosting infrastructure.

Table Of Content

  • Key Takeaways
  • BGP Hijack Diverts Softaculous Traffic
  • What You Should Do

Virtualizor is a critical component for hosting providers, enabling the management of Virtual Private Server (VPS) nodes across various virtualization technologies like KVM, Xen, LXC, OpenVZ, and Proxmox. A single Virtualizor master server can oversee hundreds of individual virtualization servers. This architecture means a compromised update at this level can profoundly impact an entire hosting stack, affecting numerous clients. The product boasts hundreds of NOC partners, underscoring the potential for widespread infrastructure disruption rather than isolated website compromises.

The BGP hijack commenced around 20:57 UTC on August 28, 2026, and concluded by 06:10 UTC on August 30. During this period, AS62390 (NexonHost) illicitly advertised the 162.55.80.0/24 IP block, a range typically utilized by Softaculous for its update and billing systems, via AS6204 (Zet.net).

BGP Hijack Diverts Softaculous Traffic

Hetzner, the legitimate owner, normally advertises a broader /16 prefix (162.55.0.0/16). The attackers leveraged a more specific /24 prefix, which BGP routing protocols prioritize, effectively redirecting traffic globally. Intriguingly, the hijacker maintained AS24940 (Hetzner) in the path tail, avoiding detection as the origin of the rogue route.

Crucially, the traffic diversion also facilitated the issuance of valid Let’s Encrypt certificates for virtualizor.com, api.virtualizor.com, and files.virtualizor.com. This prevented clients from receiving TLS warnings, making the malicious redirection appear legitimate. These domains also hosted the Softaculous client area, raising concerns that user logins during the compromise window may have been intercepted by the attackers.

Analysis of RIPE Routing Information Service (RIS) data confirms that all 368 collector peers observed the rogue route at some point. During peak activity, approximately 72% of these peers routed traffic through AS62390. The hijacking manifested in two distinct waves of activity, totaling about 22 hours, separated by an 11-hour lull after Hetzner began announcing the /24 prefix around 08:50 UTC on August 29.

The intermittent nature of the diversion, characterized by approximately 10,600 route withdrawals, limited the number of update checks that successfully completed on the attacker’s server. Virtualizor independently verified the interception on August 29, when a server on the diverted path responded for Softaculous domains using the fraudulent certificate.

Virtualizor has confirmed that its update clients lacked cryptographic verification for packages. This critical vulnerability meant that a successful BGP hijack combined with a valid TLS certificate was sufficient to allow attackers to execute arbitrary code with root privileges. While only a limited number of installations that performed update checks during the active diversion window received the malicious payload, the attacker’s server was never logged by the vendor. Consequently, Virtualizor advises that all hosts running the platform should be considered potentially compromised.

Although there is no current evidence of modifications to customer VPS guest systems, a compromised hypervisor operating at root level inherently puts every guest on that node at severe risk. Given that a Virtualizor master server oversees multiple guest VPS instances, operators cannot assume the impact was confined to the control panel. No malicious packages have been identified for other Softaculous-related products such as Webuzo, Backuply, or SitePad.

The primary indicator of compromise (IOC) identified is the presence of the file /etc/systemd/system/java-jre-update.service. Operators discovering this file are strongly advised to contact Virtualizor directly rather than attempting to delete it independently. The vendor also recommends a series of immediate security measures, including rotating API keys, restricting SSH and API access to a whitelist of trusted IP addresses, and diligently checking for any unknown user accounts, unauthorized SSH keys, or newly scheduled jobs.

Any individual who accessed the Softaculous client area during the compromise window should immediately reset their password and regenerate any associated API keys. Normal routing has since been fully restored, with no further traffic diversion detected after 06:10 UTC on August 30.

What You Should Do

  • Check for Indicator of Compromise (IOC): Immediately scan your Virtualizor installations for the file /etc/systemd/system/java-jre-update.service.
  • Contact Virtualizor: If the IOC is found, do NOT delete it. Contact Virtualizor support for guidance on remediation.
  • Reset Passwords & API Keys: All users who accessed the Softaculous client area between August 28 (20:57 UTC) and August 30 (06:10 UTC), 2026, must reset their passwords and regenerate all API keys.
  • Rotate Virtualizor API Keys: Regardless of direct compromise, rotate all Virtualizor API keys as a precautionary measure.
  • Restrict Access: Implement strict IP-based whitelisting for SSH and API access to your Virtualizor master and hypervisor servers.
  • Audit Systems: Conduct a thorough audit of all Virtualizor servers for any new or unknown user accounts, SSH keys, or scheduled tasks.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

Attack

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Anthropic Hardens Claude Security After AI Models Gain Unauthorized Access

Next Post

Cisco Routers Vulnerable to State-Sponsored Attacks, Critical Infrastructure at Risk

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Attackers Target AWS Root Accounts at 150+ Organizations with Password Spraying
September 1, 2026
Broadcom Unveils VMware AI Factory for Secure Enterprise AI Deployment
August 31, 2026
Critical D-Link Router Flaws Let Attackers Change Admin Password, Steal Wi-Fi Credentials
August 31, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us