Tech News news.wrst.click
🌐 Español
LIVE EDITORIAL
Back to all news
Artificial Intelligence · September 2, 2026 · 2 min read · The Hacker News · 4 views

BGP Hijack Compromises Virtualizor Hypervisors via Malicious Update

BGP Hijack Compromises Virtualizor Hypervisors via Malicious Update
📷 Original photo: The Hacker News View original source ↗
Summary

Virtualizor has disclosed a critical security incident where malicious actors employed a BGP hijacking attack to divert Softaculous traffic and deliver a malicious update to Virtualizor installations. The attack window extended from August 28 at 20:57 UTC to August 30 at 06:10 UTC. Hosting provider AlbaHost reported that 5 of its 34 Virtualizor hypervisor nodes sustained root-level compromise, representing approximately 15% of its infrastructure. While Virtualizor stated the incident affected "a handful of servers" rather than the general user base, the attack's nature exposes systemic vulnerabilities in software update mechanisms.

The attack mechanics exploited the lack of cryptographic verification in Virtualizor's update client. During the diversion window, the attacker obtained a valid Let's Encrypt certificate, allowing connections to display no certificate warnings. The malicious code inserted into three legitimate Virtualizor files established persistence through a root cron job executing modified code. The payload downloaded Java 17 when the runtime was absent, subsequently executing as root. Persistence was guaranteed via a systemd service, and an unauthorized account named "proxyuser" was created with a successful SSH login from IP 193.32.127[.]248.

The impact on the hosting provider ecosystem is significant. Client-area session traffic and payment entry data during the diversion window may have reached the attacker-operated server. As of September 2, Virtualizor had not reported confirmed theft of client account or payment information. The incident underscores deficiencies in software supply chain security practices, particularly the absence of cryptographic package signing as a standard feature.

In response, Virtualizor released Patch 9 on September 1 with a Security Analyzer, though cryptographic package signing remains "future work." The company recommends operators run the official scanner, rotate and restrict API credentials, and audit each server. For hosts with confirmed root compromise, the only reliable long-term remediation is a clean rebuild. This incident serves as a cautionary example of BGP attack risks and the critical need for cryptographic verification of all software updates.

← Back to all news ID: bgp-hijack-deliv
Summary copied to clipboard