← Blog · · df00tech

Malicious Virtualizor Update Delivered via BGP Hijack of Vendor Infrastructure

security-news technique

What happened

According to BleepingComputer, attackers hijacked BGP routing tied to Virtualizor's update infrastructure and used the redirected routes to serve a malicious update to the VPS management software. Virtualizor is widely used by hosting providers to manage virtual private server environments, so a compromised update channel has broad reach into infrastructure that ultimately hosts customer workloads.

Details on the exact BGP prefixes hijacked, the payload delivered, and the scope of affected deployments were not specified in the initial report, and full technical details are still emerging.

Why it matters for defenders

This is a supply-chain and network-infrastructure attack rather than an application vulnerability: even organizations running Virtualizor correctly and patched could have pulled a malicious update if their traffic was routed through the hijacked path. Because Virtualizor sits at the hypervisor/VPS management layer, a successful compromise could give an attacker a foothold with control over many downstream virtual machines — making this relevant to any hosting provider, reseller, or organization that relies on Virtualizor-managed infrastructure, even indirectly.

BGP hijacking of software update paths is also a reminder that update integrity depends on more than TLS to a hostname — routing itself is part of the trust chain.

What defenders should watch for now

  • Review Virtualizor update logs and installed package/version history for any updates applied during the reported hijack window that don't match expected release channels or checksums.
  • Check BGP monitoring/route-history services (e.g., RouteViews, RIPE RIS, or a commercial BGP monitoring tool) for anomalous announcements affecting Virtualizor's known ASNs or update-server IP ranges around the reported timeframe.
  • Where possible, validate update artifacts against vendor-published signatures or hashes rather than trusting the delivery path alone.
  • Watch for unexpected outbound connections, new administrative accounts, or configuration changes on hosts running Virtualizor following any suspicious update activity.
  • Hosting providers should confirm with Virtualizor directly whether their environment was in the affected update path, since public reporting may not cover full scope.

Developing situation

This is a net-new report and many specifics — affected version ranges, indicators of compromise, and remediation guidance from Virtualizor — had not been published at the time of writing. Defenders should treat this as early-stage intelligence and monitor for vendor advisories. Original reporting: BleepingComputer.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.