BGP hijack delivered malicious Virtualizor update

A BGP hijack rerouted Softaculous update traffic to attacker servers Aug. 28–30; a valid TLS certificate allowed a malicious Virtualizor update to be delivered to a small number of servers.

Softaculous reported that between Aug. 28 and Aug. 30 a block of its IP addresses was redirected to attacker-controlled infrastructure by a BGP hijack, and a valid TLS certificate obtained during the incident allowed a malicious Virtualizor update to be served to some installations.

The incident began at about 20:57 UTC on Aug. 28 when autonomous system AS62390 (NexonHost) announced a more specific route that covered part of Hetzner’s address space, including IPs used by Softaculous. Because the route was more specific than Hetzner’s usual 162.55.0.0/16 announcement, networks that accepted the route sent traffic to the attacker’s infrastructure. The announcement retained AS24940 (Hetzner) on the AS path, which made the route appear plausible to many networks.

Let’s Encrypt’s automated domain validation was also routed through the hijack, and the attacker obtained a technically valid TLS certificate for Softaculous domains. That certificate allowed the attacker-controlled servers to present valid TLS credentials, preventing browsers and client software from warning about the redirection.

Softaculous said the affected IP addresses supported software updates, client-area billing and other services. Traffic was intermittently diverted for roughly 22 hours, with an 11-hour period in the middle of the incident when almost no diversion occurred. Only Virtualizor instances that checked for and applied updates while their traffic was rerouted received the tampered package, the company reported.

Softaculous noted its update clients did not cryptographically verify update packages at the time, so a modified package would not have been rejected on that basis. The company cannot provide a definitive list of affected servers and recommended that administrators treat all Virtualizor installations as potentially in scope for checks and remediation.

The vendor published indicators of compromise and advised administrators to reset client-area passwords, review account activity and regenerate API keys. Softaculous released Virtualizor version 3.2.9.9, which includes a mitigation tool for known exploits, and said it will implement package code signing to cryptographically validate future updates. The company reported it has fully restored traffic to its legitimate servers and has not identified a malicious package for any other product, while its investigation continues.

Virtualizor is a web-based control panel used by hosting providers and VPS operators to install and manage virtual machines and related applications. Softaculous provides an auto-installer for more than 400 web applications and operates update and billing infrastructure implicated in the hijack. Because the malicious traffic did not reach internal logs, the vendor urged all Virtualizor operators to perform forensic checks and apply the provided mitigations.

Articles by this author