Malware & Threats

Malicious Virtualizor Update Served via BGP Hijacking

Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates.

TLS certificate lifespan

Softaculous’ Virtualizor users were served malicious software updates for two days after a threat actor diverted internet traffic to attacker-controlled servers.

A provider of applications for web hosting, Softaculous offers an auto-installer tool for over 400 popular web applications. Virtualizor is its web-based Virtual Server (VPS) management control panel.

Between August 28 and August 30, a block of Softaculous IP addresses was hit by a BGP hijack attack: a threat actor used a technically valid TLS certificate for the company’s domains to divert traffic to attacker infrastructure.

The IP addresses affected by the BGP hijack, Softaculous says, were used for software updates, client area/billing, and other services.

“We have confirmed that a malicious Virtualizor update package was delivered to a small number of installations that checked for updates while their traffic was being diverted. This affected a handful of servers rather than the general Virtualizor user base,” the company says.

Softaculous encourages all Virtualizor operators to check for potential compromises, as it cannot tell how many servers might have been affected. The malicious traffic never reached the company’s logs.

Advertisement. Scroll to continue reading.

“We have not identified a malicious package for any other product; that investigation is ongoing,” the company notes, adding that it has fully restored traffic to its legitimate servers.

The BGP hijack started at approximately 20:57 UTC on 28 August 2026, when AS62390 (NexonHost) began announcing a portion of German web hosting provider and data center operator Hetzner’s address space, including IP addresses for Softaculous systems.

“This announcement was more specific than Hetzner’s normal announcement of the surrounding block (162.55.0.0/16), so under standard BGP route selection it took precedence on every network that accepted it. The announcement retained AS24940 (Hetzner) on the AS path as the apparent origin,” Softaculous notes.

Next, the threat actor obtained a valid TLS certificate for Softaculous domains from Let’s Encrypt, “because the certificate authority’s automated domain-ownership validation was also routed through the hijack,” the company explains.

The hijacker could then redirect traffic to their server without triggering a browser or client certificate warning.

According to Softaculous, only a small number of Virtualizor instances were served a malicious package: those that checked for an update and completed it during the hijack window. The traffic was intermittently diverted for 22 hours (and almost no diversion occurred during an 11-hour window mid-incident).

“Our product update clients did not yet cryptographically verify update packages, so a modified package would not have been rejected on that basis. We believe only a small number of servers were actually affected, but we cannot produce a definitive list, so please treat every Virtualizor server as in scope for checks,” the company notes.

Softaculous has provided a known indicator of compromise (IoC) and encourages users to reset their client-area passwords, review their account activity, and regenerate their API keys.

The company has released a version of Virtualizor 3.2.9.9 containing a mitigation tool for known exploits and is implementing a code signing mechanism for all packages.

Related: Rust Supply Chain Attack Linked to North Korean Hackers

Related: Trivy, Not LiteLLM Behind the 2,500 Org Compromise

Related: Fortune 500 Companies Hit in Azure Data Theft Campaign

Related: Critical Flaw Allowed to Azure Cosmos DB Pwnage

Related Content

ICS/OT

Cisco Talos has disclosed the details of apparently unpatched vulnerabilities in MC Technologies industrial routers and the GoCast BGP tool.

Government

The White House has released a roadmap for addressing internet routing (BGP) security issues, mainly through RPKI adoption.

Network Security

The FCC proposes that broadband providers plan for BGP security and provide quarterly reports on implemented risk mitigations.

Mobile & Wireless

Orange Spain’s internet went down for several hours after its RIPE account was hacked, likely after malware stole the credentials.

Network Security

Open source BGP implementation FRRouting is affected by three vulnerabilities that can be exploited to cause disruption via DoS attacks.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version