Last week, cyber attackers executed a BGP routing hijack targeting Softaculous, redirecting traffic to distribute a malicious Virtualizor update. This incident, reported by a vendor, impacted several hypervisor servers.
Impact on Hosting Providers
Virtualizor is crucial for managing VPS nodes across platforms like KVM, Xen, LXC, OpenVZ, and Proxmox. A single master server can oversee hundreds of virtualization servers, making the malicious update a significant threat to hosting infrastructure, rather than isolated website panels. The product’s extensive list of network operations center (NOC) partners further highlights the potential for widespread impact.
The hijack occurred between 20:57 UTC on August 28, 2026, and 06:10 UTC on August 30. The attackers used AS62390 (NexonHost) to announce 162.55.80.0/24, a Hetzner block, through AS6204 (Zet.net), affecting Softaculous update and billing systems.
Routing Details and TLS Exploitation
Normally, Hetzner advertises 162.55.0.0/16, but the hijackers’ more specific prefix took precedence. By keeping AS24940 (Hetzner) in the routing path, they avoided detection as the origin. The diversion allowed the attackers to obtain a legitimate Let’s Encrypt certificate for Virtualizor domains, preventing TLS warnings and compromising client logins during the attack window.
According to RIPE RIS data, all 368 collector peers carried the rogue route at some point, with about 72% of them selecting the hijacked path during active phases. The diversion was intermittent due to approximately 10,600 withdrawals, limiting the number of update checks completed on the attacker’s server.
Security Measures and Recommendations
Virtualizor confirmed the interception on August 29, noting that its update clients did not cryptographically verify packages, making the hijack effective in executing attacker code. Although only a few installations received the malicious payload, the incident underscores the vulnerability of root-compromised hypervisors.
Operators are advised to treat every Virtualizor host as potentially compromised. The known indicator of compromise is the presence of /etc/systemd/system/java-jre-update.service. Virtualizor recommends contacting the vendor if found, rather than deleting it, and suggests rotating API keys, restricting SSH and API access to trusted IPs, and auditing for unknown accounts or scheduled jobs.
Users who accessed the Softaculous client area during the breach should reset passwords and regenerate API keys. Routing has since been restored, with no further diversions after 06:10 UTC on August 30.
Proactive threat intelligence and rapid incident response are essential to prevent future security breaches. Integrating threat intelligence into security operations centers (SOCs) can enhance defense mechanisms against such attacks.
