Interestana
Home/News/Hackers Hijack BGP to Distribute Malicious Virtualizor Updates
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Hackers Hijack BGP to Distribute Malicious Virtualizor Updates

Cybercriminals successfully distributed a malicious update for the Virtualizor Virtual Private Server (VPS) management software by exploiting a Border Gateway Protocol (BGP) hijacking attack. This sophisticated attack involved manipulating internet routing to redirect legitimate update requests from Virtualizor users to attacker-controlled servers. The compromised update contained a backdoor, allowing unauthorized access to servers managed by Virtualizor. The incident, which came to light on June 10, 2024, highlights a significant vulnerability in how software updates are delivered and secured, particularly for infrastructure management tools used widely in the hosting industry. Virtualizor is a comprehensive control panel designed to help hosting providers manage their VPS environments efficiently, offering features for provisioning, billing, and server administration. Its widespread adoption means that a compromise of its update mechanism can have far-reaching consequences for a large number of end-users and hosting companies. The attackers leveraged BGP hijacking, a technique where an autonomous system (AS) falsely announces its ownership of IP address blocks, to reroute traffic intended for Virtualizor's legitimate update servers. This allowed them to intercept update requests and serve their malicious payload instead. Upon installation, the compromised update installed a backdoor, granting attackers the ability to execute arbitrary commands on affected servers. This backdoor could be used for a variety of malicious purposes, including data theft, further network intrusion, or deploying ransomware. The security researchers who uncovered the attack noted that the attackers specifically targeted the update infrastructure, indicating a well-planned operation. The incident underscores the critical need for robust security measures throughout the software supply chain, from development to distribution. Hosting providers and software vendors are urged to implement multi-factor authentication for update servers, employ digital signatures for all software releases, and continuously monitor their network infrastructure for any signs of BGP manipulation or unauthorized traffic redirection. The full extent of the compromise is still being investigated, but the potential impact is significant given Virtualizor's role in managing critical server infrastructure for numerous organizations globally. This event serves as a stark reminder of the evolving tactics employed by cybercriminals and the persistent threats to the integrity of software updates.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next