← Blog · · df00tech

BGP Hijack Used to Push Malicious Virtualizor Update, Granting Root Access to Some Hypervisors

security-news technique

Virtualizor, the hypervisor control panel widely used by hosting providers, has disclosed that attackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous update traffic. The diverted traffic was used to deliver a malicious Virtualizor package to some installations, with the incident window running from approximately August 28 at 20:57 onward. One hosting provider separately reported that 5 of 34 checked Virtualizor hypervisors sustained root-level compromise.

Why It Matters

This is a supply-chain-style attack at the network layer rather than the code-repository layer: rather than compromising a build system or package registry, the attackers reportedly manipulated internet routing itself to intercept and replace legitimate update traffic. Because Virtualizor manages hypervisors, successful compromise can translate directly into root access on host systems — and potentially every VM running on top of them. Hosting providers and any organization running Virtualizor-managed infrastructure should treat this as a potential full-stack compromise scenario, not an isolated application bug.

What Defenders Should Watch For

  • Review Virtualizor update/patch logs for activity during and after the reported incident window (starting ~2026-08-28 20:57) for unexpected package installs or version changes not matching your normal update cadence.
  • Audit hypervisor hosts for unauthorized root accounts, new SSH keys, unexpected cron jobs, or modified system binaries — signs consistent with persistent root access.
  • Check historical BGP routing/announcement data (e.g., via public route-monitoring services) for anomalous announcements affecting networks used to reach Softaculous/Virtualizor update infrastructure around the incident window.
  • Where feasible, validate update package integrity (signatures/checksums) rather than trusting delivery channel alone, and consider pinning or manually verifying updates for critical hypervisor management software until vendor guidance is finalized.
  • If you operate hosting infrastructure, inventory and inspect all Virtualizor instances rather than assuming a clean bill of health from a partial sample — the reported provider found compromise in roughly 15% of hosts checked.

This is a developing story based on vendor and provider disclosures, and further technical detail (indicators of compromise, full scope, root cause of the BGP hijack) may still emerge. This is not tied to a specific CVE at this time. For the original report, see The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.