Malicious Virtualizor Update Served via BGP Hijacking
A threat actor leveraged a BGP hijacking attack to deliver a malicious Virtualizor update package to a small number of Softaculous users. The attack involved diverting internet traffic through a compromised TLS certificate, allowing the attacker to serve a modified update without triggering security warnings. Softaculous has identified IoCs and implemented mitigations, including code signing and password resets.
Softaculous’ Virtualizor users were briefly exposed to a malicious software update due to a BGP hijacking attack. Virtualizor is Softaculous’ web-based Virtual Server (VPS) management control panel, offering an auto-installer tool for over 400 popular web applications. Between August 28 and August 30, a block of Softaculous IP addresses was targeted by a BGP hijack attack, where a threat actor diverted internet traffic to attacker-controlled servers using a technically valid TLS certificate for Softaculous domains. This certificate was obtained through Let’s Encrypt, as the certificate authority’s automated domain-ownership validation was also routed through the hijack.
The hijacker could then redirect traffic to their server without triggering a browser or client certificate warning. According to Softaculous, only a small number of Virtualizor instances were served a malicious package – those that checked for an update and completed it during the hijack window. The traffic was intermittently diverted for 22 hours, with almost no diversion occurring during an 11-hour window mid-incident.
Softaculous notes that their product update clients did not yet cryptographically verify update packages, so a modified package would not have been rejected on that basis. The company has provided a known indicator of compromise (IoC) and encourages users to reset their client-area passwords, review their account activity, and regenerate their API keys.
Softaculous has released a version of Virtualizor 3.2.9.9 containing a mitigation tool for known exploits and is implementing a code signing mechanism for all packages. The incident began at approximately 20:57 UTC on 28 August 2026, when AS62390 (NexonHost) began announcing a portion of German web hosting provider and data center operator Hetzner’s address space, including IP addresses for Softaculous systems. The announcement was more specific than Hetzner’s normal announcement of the surrounding block (162.55.0.0/16), so under standard BGP route selection it took precedence on every network that accepted it. The announcement retained AS24940 (Hetzner) on the AS path as the apparent origin.