By Interestana AI Editorial — AI-drafted, human-overseen. How we report
BGP Hijack Delivers Malicious Virtualizor Update

Virtualizor has reported that malicious actors successfully executed a Border Gateway Protocol (BGP) hijack to compromise its services. The attackers exploited this BGP hijack to divert traffic intended for Softaculous, a popular one-click installer for web applications. By intercepting and manipulating this legitimate update channel, the hackers were able to inject a malicious Virtualizor package into the update stream. This compromised update was then delivered to a subset of Virtualizor installations, granting the attackers unauthorized access.
Following the incident, a hosting provider independently verified the impact of the attack. This provider conducted an investigation and checked 34 of its Virtualizor hypervisors. The investigation revealed that 5 of these hypervisors had sustained a root-level compromise. This indicates that the malicious update enabled the attackers to achieve persistent and elevated privileges on the affected systems. The incident window during which the BGP hijack and subsequent malicious update delivery occurred was identified as beginning around August 28 at 20:57 UTC. The exact duration of the hijack and the total number of affected installations have not been fully disclosed by Virtualizor, but the hosting provider's findings highlight a significant security breach.
Border Gateway Protocol (BGP) is a fundamental routing protocol of the internet that exchanges routing and reachability information among autonomous systems. A BGP hijack, also known as BGP hijacking or BGP route hijacking, occurs when an attacker announces incorrect routing information to the internet, causing traffic intended for one destination to be misrouted to the attacker's network. This technique is highly disruptive and can be used for various malicious purposes, including denial-of-service attacks, man-in-the-middle attacks, and, as demonstrated in this case, the distribution of malware or malicious updates. The ability to hijack BGP traffic underscores the vulnerabilities in internet routing infrastructure and the potential for sophisticated attacks against critical services.
Virtualizor is a web hosting control panel that provides a platform for managing virtual machines and servers. It is widely used by hosting providers to offer services such as VPS (Virtual Private Server) hosting. The compromise of Virtualizor installations means that the underlying virtual machines and the data they host could be at risk. Persistent root access allows attackers to install backdoors, steal sensitive data, disrupt services, or use the compromised servers for further malicious activities, such as launching attacks against other targets. The incident serves as a stark reminder of the importance of robust security measures, including network monitoring and incident response, for both service providers and their customers.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.