Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Malicious Update Exploits BGP Hijack in Virtualizor

Malicious Update Exploits BGP Hijack in Virtualizor

Posted on September 2, 2026 By CWS

A recent security incident involving Virtualizor has come to light, where hackers exploited a Border Gateway Protocol (BGP) hijack to intercept Softaculous traffic. This diversion allowed attackers to distribute a malicious update to some Virtualizor installations, leading to root-level compromises in several systems. Notably, a hosting provider has reported that five of its 34 examined Virtualizor hypervisors were affected.

Incident Details and Timeline

The unauthorized activities were detected between August 28 at 20:57 UTC and August 30 at 06:10 UTC. Virtualizor has urged all operators to inspect their servers since an exhaustive list of affected installations or versions remains unavailable. To address the situation, Virtualizor issued Patch 9 with a Security Analyzer on September 1, although cryptographic signing of packages is still a work in progress. Operators are advised to utilize the official scanner, update API credentials, and thoroughly audit servers for any unauthorized access or persistence.

Technical Aspects of the Attack

The BGP hijack resulted in traffic redirection to servers controlled by the attackers. These servers acquired a valid Let’s Encrypt certificate, preventing any certificate warnings during connections. Virtualizor installations that checked for updates during this period might have received the tampered package due to the absence of cryptographic verification mechanisms. AlbaHost, a provider on LowEndTalk, revealed that malicious commands were embedded in legitimate Virtualizor files, executed later via a root cron job.

Key modifications included the addition of an attacker-controlled key to the root account and the installation of Java 17 if missing, followed by the execution of a payload as root. This payload created persistence using a systemd service and established an unauthorized account called ‘proxyuser’. Anomalies were noted with SSH logins from an IP address linked to the attackers.

Recommendations for Virtualizor Operators

Virtualizor has outlined several steps for operators to secure their systems. These include checking for specific systemd units, rotating API keys, auditing unknown SSH keys, and restricting access to trusted IPs. The official scanner, which has a specific SHA-256 hash for verification, should be employed to identify indicators of compromise (IoCs). Operators are advised to contact support before taking remediation actions to preserve evidence.

Some IoCs include the presence of specific files and injected strings in core Virtualizor files. If a root compromise is confirmed, a complete system rebuild is recommended for long-term security.

Future Outlook and Security Measures

As investigations continue, Virtualizor emphasizes the need for vigilance and comprehensive server audits. While no client data theft has been confirmed, users who logged in or entered payment details during the incident should take precautionary measures, such as changing passwords and reviewing account activity. Virtualizor’s ongoing inquiry aims to provide further clarity and enhance security measures to prevent similar breaches in the future.

The Hacker News Tags:API credentials, BGP hijack, Cybersecurity, IoCs, malicious update, network security, root access, security patch, Softaculous, system compromise, Virtualizor

Post navigation

Previous Post: Hackers Bypass Microsoft Defender with Fake Installers
Next Post: Rockwell Automation Fixes Critical Software Vulnerabilities

Related Posts

Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet The Hacker News
Severe Bugs in AI Code Editor Risk System Intrusion Severe Bugs in AI Code Editor Risk System Intrusion The Hacker News
AI-Driven Browser Ransomware Exploits Chromium API AI-Driven Browser Ransomware Exploits Chromium API The Hacker News
New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands The Hacker News
Microsoft Addresses 138 Security Flaws, Including Critical DNS and Netlogon Issues Microsoft Addresses 138 Security Flaws, Including Critical DNS and Netlogon Issues The Hacker News
Cybersecurity Threats Intensify with New Vulnerabilities Cybersecurity Threats Intensify with New Vulnerabilities The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Assists in Exploit Development for WAGO PLCs
  • Rockwell Automation Fixes Critical Software Vulnerabilities
  • Malicious Update Exploits BGP Hijack in Virtualizor
  • Hackers Bypass Microsoft Defender with Fake Installers
  • Urgent Patch Needed for Cleo Harmony Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Assists in Exploit Development for WAGO PLCs
  • Rockwell Automation Fixes Critical Software Vulnerabilities
  • Malicious Update Exploits BGP Hijack in Virtualizor
  • Hackers Bypass Microsoft Defender with Fake Installers
  • Urgent Patch Needed for Cleo Harmony Security Flaw

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark