Malicious Virtualizor Update Served via BGP Hijacking
BGP hijacking used to serve malicious Virtualizor updates via compromised TLS certificates.
Summary
A threat actor exploited a BGP hijacking attack to divert traffic to malicious servers, serving compromised Virtualizor software updates. The attackers used a valid TLS certificate obtained through the hijack to avoid browser warnings. While only a small number of installations were affected, Softaculous urges all users to check for compromises and reset credentials.
Full text
Softaculous’ Virtualizor users were served malicious software updates for two days after a threat actor diverted internet traffic to attacker-controlled servers. A provider of applications for web hosting, Softaculous offers an auto-installer tool for over 400 popular web applications. Virtualizor is its web-based Virtual Server (VPS) management control panel. Between August 28 and August 30, a block of Softaculous IP addresses was hit by a BGP hijack attack: a threat actor used a technically valid TLS certificate for the company’s domains to divert traffic to attacker infrastructure. The IP addresses affected by the BGP hijack, Softaculous says, were used for software updates, client area/billing, and other services. “We have confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted. This affected a handful of servers rather than the general Virtualizor user base,” the company says. Softaculous encourages all Virtualizor operators to check for potential compromises, as it cannot tell how many servers might have been affected. The malicious traffic never reached the company’s logs.Advertisement. Scroll to continue reading. “We have not identified a malicious package for any other product; that investigation is ongoing,” the company notes, adding that it has fully restored traffic to its legitimate servers. The BGP hijack started at approximately 20:57 UTC on 28 August 2026, when AS62390 (NexonHost) began announcing a portion of German web hosting provider and data center operator Hetzner’s address space, including IP addresses for Softaculous systems. “This announcement was more specific than Hetzner’s normal announcement of the surrounding block (162.55.0.0/16), so under standard BGP route selection it took precedence on every network that accepted it. The announcement retained AS24940 (Hetzner) on the AS path as the apparent origin,” Softaculous notes. Next, the threat actor obtained a valid TLS certificate for Softaculous domains from Let’s Encrypt, “because the certificate authority’s automated domain-ownership validation was also routed through the hijack,” the company explains. The hijacker could then redirect traffic to their server without triggering a browser or client certificate warning. According to Softaculous, only a small number of Virtualizor instances were served a malicious package: those that checked for an update and completed it during the hijack window. The traffic was intermittently diverted for 22 hours (and almost no diversion occurred during an 11-hour window mid-incident). “Our product update clients did not yet cryptographically verify update packages, so a modified package would not have been rejected on that basis. We believe only a small number of servers were actually affected, but we cannot produce a definitive list, so please treat every Virtualizor server as in scope for checks,” the company notes. Softaculous has provided a known indicator of compromise (IoC) and encourages users to reset their client-area passwords, review their account activity, and regenerate their API keys. The company has released a version of Virtualizor 3.2.9.9 containing a mitigation tool for known exploits and is implementing a code signing mechanism for all packages. Related: Rust Supply Chain Attack Linked to North Korean Hackers Related: Trivy, Not LiteLLM Behind the 2,500 Org Compromise Related: Fortune 500 Companies Hit in Azure Data Theft Campaign Related: Critical Flaw Allowed to Azure Cosmos DB Pwnage Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Hackers Start Exploiting Critical Langflow VulnerabilityFive Venezuelans Plead Guilty in US Court to ATM JackpottingRansomware Gang Claims Nutex Health Data Breach9.5 Million Impacted by Aesto Health Data BreachWatchGuard Patches Critical VulnerabilitiesServiceNow Patches 3 Critical Code Injection VulnerabilitiesMcKesson Confirms Data Breach as Attacker Deadline LoomsCritical Ruby on Rails Vulnerability in Attackers’ Crosshairs Latest News Anthropic Details Response to Security Incidents, Unveils Enterprise SafeguardsOpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity ThresholdChrome and Firefox Updates Patch Dozens of Vulnerabilities23-Year-Old Sality P2P Botnet DisruptedSonicWall Warns of Two SMA1000 Zero-Days Exploited in AttacksPalo Alto Networks Acquires AI Agent Platform ConsoleSevii Targets AI-Speed Attacks With Preemptive Autonomous DefenseCoast Guard Establishes Office of Maritime Cybersecurity Policy Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveSectigo has named Ian Hassard as Chief Product Officer.Australian Securities Exchange has appointed Hanlie Botha as Deputy Chief Information Security Officer.Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- domain — softaculous.com