BGP Hijack Diverts Softaculous Traffic to Deliver Malicious Virtualizor Update

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

Attackers hijacked BGP routing for Softaculous last week and delivered a malicious Virtualizor update to a handful of hypervisor servers, according to a vendor incident report.

Hosting providers use Virtualizor to manage VPS nodes on KVM, Xen, LXC, OpenVZ, and Proxmox, and a single master can control hundreds of virtualization servers, placing a poisoned update high in the hosting stack. The product publicly lists hundreds of NOC partners, so a compromise here hits hosting infrastructure rather than a single website panel.

The hijack ran from about 20:57 UTC on 28 August 2026 until 06:10 UTC on 30 August. AS62390 (NexonHost) announced 162.55.80.0/24, a Hetzner block used by Softaculous update and billing systems, through AS6204 (Zet.net).

BGP Hijack Diverts Softaculous Traffic

Hetzner normally advertised only 162.55.0.0/16, so the more-specific prefix won everywhere it propagated. The hijacker kept AS24940 (Hetzner) on the path tail rather than appearing as origin.

Diverted Let’s Encrypt validation produced a valid certificate for virtualizor.com, api.virtualizor.com, and files.virtualizor.com, so clients showed no TLS warning. Those addresses also served the Softaculous client area, so logins during the window may have reached the attacker.

RIPE RIS data shows all 368 collector peers carried the rogue route at some point. During active waves, about 72 percent of that set had a best path through AS62390. Two flapping waves totaling roughly 22 hours were split by an 11-hour lull after Hetzner announced the /24 around 08:50 UTC on 29 August.

About 10,600 withdrawals made diversion intermittent, which limited how many update checks completed on the attacker’s server. The vendor independently confirmed interception on 29 August, when a host on the diverted path answered for Softaculous domains with the fraudulent certificate.

Virtualizor says its update clients did not cryptographically verify packages, so a hijack plus valid TLS was enough to run attacker code as root. Only a small number of installations that checked for updates during a diverted interval received the payload. The attacker’s server never hit vendor logs, so every Virtualizor host should be treated as in scope.

There is no evidence customer VPS guests were modified, but a root-compromised hypervisor puts every guest on that node at risk. Because a Virtualizor master sits above guest VPS instances, operators cannot assume the blast radius stopped at the control panel. No malicious package has been identified for Webuzo, Softaculous, Backuply, or SitePad.

The known indicator is /etc/systemd/system/java-jre-update.service. Operators who find it should contact the vendor rather than deleting it. Virtualizor also recommends rotating API keys, locking SSH and API access to trusted addresses, and checking for unknown accounts, keys, and scheduled jobs.

Anyone who used the Softaculous client area during the window should reset that password and regenerate API keys. Routing has been restored, with no further diversion after 06:10 UTC on 30 August.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

The post BGP Hijack Diverts Softaculous Traffic to Deliver Malicious Virtualizor Update appeared first on Cyber Security News.