Virtualizor BGP Hijacking

Jade @ Absolute Hosting

Absolute Hosting Representative
Company Rep
Company Rep
Joined
Nov 17, 2015
Messages
2,038
Reaction score
1,464
Location
Centurion
Dear Customer,



We are writing to inform you about a security incident involving a BGP hijacking that affected a block of IP addresses used by Softaculous services, including infrastructure serving Virtualizor.



Incident Summary

Between 28 August 2026 ~20:57 UTC and 30 August 2026 ~06:10 UTC, an unauthorized network announcement diverted traffic destined for 162.55.80.0/24 to an attacker-controlled server. The affected infrastructure included our software update endpoint and client-area services.

What Happened



Traffic was redirected through a BGP hijack





An unrelated network began announcing our IP range using a more-specific BGP route. This caused traffic from some networks to be redirected to an attacker-controlled server. The attacker also obtained a technically valid TLS certificate for our domains, so affected connections did not display a certificate warning.



Virtualizor

Malicious Update Package

A malicious Virtualizor update package was delivered to a small number of installations whose update requests completed while traffic was diverted.

Routing Status

Fully Restored

The unauthorized route was withdrawn and normal routing was restored globally on 30 August at approximately 06:10 UTC.

Action Required

If you run Virtualizor, please check your server 1. Check for the indicator of compromise: look for /etc/systemd/system/java-jre-update.service. If it is present, do not simply delete it; contact us.



2. Rotate Virtualizor API credentials: reset all API keys, restrict API access to trusted IP addresses, and remove any key you do not recognize.



3. Audit access: review SSH keys, user accounts, scheduled tasks, cron jobs, and unexpected outbound connections. Restrict SSH access to trusted IP addresses.



4. Run our security scan: Virtualizor Security Scan https://files.virtualizor[.]com/security/virtualizor_security_scan.sh



5. If you find signs of compromise, contact support before remediation so we can help preserve evidence.

Other Softaculous Products



No malicious package identified





We have not identified a malicious package for Webuzo, Softaculous, Backuply, SitePad, or our other products. As a precaution, if one of these servers performed an update check during the incident window, please verify the server for anything suspicious and contact us if you find anything unusual.



Client Area & API Keys

If you logged into the Softaculous client area or entered payment details during the incident window, your session may have been diverted. We recommend resetting your client-area password. As a precaution, regenerate the client area NOC API keys and update them on your servers.

Full Incident Report



Detailed timeline, measurements and findings





We have reconstructed the incident using public routing data, including the timeline, impact measurements, indicators of compromise, and the actions we recommend. Please read the full report for complete details.



Read the Full Security Report https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
 
The fact that ISPs still enable BGP hijacking is just....

The attacker also obtained a technically valid TLS certificate for our domains
This is of far greater concern. You would need elevated access in a domain to produce a valid CSR. Sounds more like someone is in the habit of leaving full PFX exposed for all to take and abuse as they wish.
 
Top
Sign up to the MyBroadband newsletter
X