Hackers used BGP hijacking to deliver malicious Virtualizor update

 

Hackers used BGP hijacking to deliver malicious Virtualizor update

Hackers compromised the update infrastructure used by Virtualizor, a VPS management tool from Softaculous, and deployed a malicious software update to a small number of servers.

The attack took place between August 28 and August 30. The attackers hijacked BGP routes for IP addresses hosted by Hetzner, allowing them to redirect traffic intended for Softaculous's update systems and client portal to malicious servers.

Softaculous said only a handful of Virtualizor installations received the malicious update. Because the traffic was redirected to the attackers, the company does not have complete logs of the affected systems.

The vendor recommends administrators to check for the file /etc/systemd/system/java-jre-update.service. If it is found, admins should rotate API credentials and check their servers for unauthorized SSH keys, accounts, scheduled tasks, and network connections.

Users who logged into the Softaculous client portal or entered payment information during the attack should also change their passwords, review account activity, and monitor their payment cards.

Softaculous says the routing issue has been fixed and the fraudulent certificate has been reported for revocation. A new Virtualizor version 3.2.9.9 was released on September 1 with a new Security Analyzer tool.

The company says it plans to add cryptographic signing to its software packages and move its update infrastructure to more secure systems.

Back to the list