BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Attackers used a BGP hijack to divert Softaculous traffic and push a malicious Virtualizor update granting root persistence on some hypervisors.
Virtualizor reported that a BGP hijack between August 28 20:57 UTC and August 30 06:10 UTC diverted Softaculous update traffic to an attacker-operated server holding a valid Let's Encrypt certificate. Installations checking for updates during the window could receive a malicious package that added an attacker SSH key to root, created a proxyuser account, and installed a Java payload persisted via a systemd service. Hosting provider AlbaHost confirmed 5 of its 34 Virtualizor hypervisors were root-compromised. Virtualizor shipped Patch 9 with a Security Analyzer on September 1, but cryptographic package signing remains future work.
- Incident window: August 28 20:57 UTC to August 30 06:10 UTC; no affected-version range identified.
- Payload persisted via /etc/systemd/system/java-jre-update.service with C2 domains cdn.nerat.cc and connect.ne-rat.xyz.
- Operators told to run the official scanner, rotate API keys, and audit SSH keys, cron jobs, and users.
- Client-area users who logged in or entered payment details during the window should reset passwords and review statements.
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | cdn.nerat.cc | le - /usr/local/virtualizor/zzvirtservice Injected string - cdn[.]nerat[.]cc/installer/widdow.jar Injected string - connect[.]ne-rat |
| domain | connect.ne-rat.xyz | g - cdn[.]nerat[.]cc/installer/widdow.jar Injected string - connect[.]ne-rat[.]xyz Injected string - jre-runtime.dat Command-and-control ( |
| ipv4 | 3.2.9.9 | anches. The incident advisory names the release Virtualizor 3.2.9.9 , while the release note calls it Virtualizor 3.2.9 (Releas |
| sha256 | 73e74402b3a61c7bab289fc11347bd54c7fcdc2fa2e410f4c3de9d6cd7377d48 | n the official scanner , whose retrieved-script SHA-256 was 73e74402b3a61c7bab289fc11347bd54c7fcdc2fa2e410f4c3de9d6cd7377d48 when checked on September 2, 2026. Contact support before r |
| sha256 | b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46998789bdc944a7870c7 | oad - /usr/lib/jvm/.cache/jre-runtime.dat Payload SHA-256 - b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46998789bdc944a7870c7 Marker file - /usr/lib/jvm/.cache/.installed Marker file - |
Full article886 words · extracted from thehackernews.com · click to collapse

Swati Khandelwal Sep 02, 2026 Network Security / Supply Chain Attack
Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked Virtualizor hypervisors sustained root-level compromise.
The incident window ran from approximately August 28 at 20:57 Coordinated Universal Time (UTC) to August 30 at 06:10 UTC. Virtualizor said every operator should check its servers because the company has no affected-version range or definitive list of installations that received the package.
Virtualizor released Patch 9 with a Security Analyzer on September 1, but the vendor said cryptographic package signing remained future work. Operators should run the official scanner, rotate and restrict application programming interface (API) credentials, and audit each server for persistence and unauthorized access.
"This affected a handful of servers rather than the general Virtualizor user base," Virtualizor said in its incident advisory .
The first route announcement containing the vendor-identified path appeared at 20:57:30 UTC on August 28, The Hacker News confirmed using RIPE Stat data . Virtualizor said the route was unauthorized. Traffic for Softaculous services was diverted to an attacker-operated server.
The attacker obtained a valid Let's Encrypt certificate during the diversion window. Connections routed through the server therefore displayed no certificate warning. A Virtualizor installation that checked for updates during a diverted interval could receive the modified package. The update client lacked cryptographic package verification, so it did not reject the package on that basis.
The AlbaHost account, displayed as a Member and Patron Provider on LowEndTalk, said malicious commands had been inserted into three legitimate Virtualizor files. A root cron job later executed the modified code.
"We can confirm that 5 of our 34 Virtualizor hypervisor nodes contained the same malicious modifications described in this thread," the AlbaHost account said.
The injected code added an attacker-controlled key to the root account. It installed Java 17 when the runtime was absent. It downloaded the Java payload. The payload was then executed as root.
The payload established persistence through a systemd service. It also created an unauthorized account named proxyuser . A successful password-based Secure Shell (SSH) login to that account from 193.32.127[.]248 appeared in the provider's logs.
In its examined environment, the AlbaHost account said it had no confirmed modification of customer virtual private servers and had not independently confirmed a database export.
Client-area sessions and payment-entry traffic during the diversion window may have reached the attacker-operated server, Virtualizor said. As of September 2, the vendor had not reported confirmed client-account or payment-data theft.
The vendor's guidance applies to the following groups -
Virtualizor operators - Check every server because no affected-version range or definitive affected-server list is available.
Client-area users who logged in or entered payment details during the incident window - Reset the client-area password, change it anywhere it was reused, review account activity, and review card statements if payment details were entered during the incident window. Client Center API users should regenerate their keys and update them on their servers.
Other Softaculous product operators - Check Webuzo, Softaculous, Backuply, SitePad, and other product servers that performed an update check during the incident window. The vendor had not identified a malicious package for those products and said its investigation remained open.
What Virtualizor Operators Should Do
Virtualizor advised operators to perform the following steps -
Check for /etc/systemd/system/java-jre-update.service . If present, preserve the evidence and contact Virtualizor support.
Rotate all Virtualizor API keys, restrict API access to trusted Internet Protocol (IP) addresses, and remove unrecognized keys.
Audit unknown SSH keys, new users, scheduled tasks or cron jobs, and unexpected outbound connections, and restrict SSH to trusted IP addresses.
Run the official scanner , whose retrieved-script SHA-256 was 73e74402b3a61c7bab289fc11347bd54c7fcdc2fa2e410f4c3de9d6cd7377d48 when checked on September 2, 2026.
Contact support before remediating a positive host so evidence can be preserved. Treat scanner containment as containment of known indicators. Perform further remediation to restore host trust.
The vendor's scanner checks the following indicators of compromise (IoCs) -
Systemd unit - /etc/systemd/system/java-jre-update.service
Installed payload - /usr/lib/jvm/.cache/jre-runtime.dat
Payload SHA-256 - b81a4e1fab9fc4e404d57224fe71e2c143aa93942bd46998789bdc944a7870c7
Marker file - /usr/lib/jvm/.cache/.installed
Marker file - /tmp/widdow.jar
Core file - /usr/local/virtualizor/globals.php
Core file - /usr/local/virtualizor/_universal.php
Core file - /usr/local/virtualizor/zzvirtservice
Injected string - cdn[.]nerat[.]cc/installer/widdow.jar
Injected string - connect[.]ne-rat[.]xyz
Injected string - jre-runtime.dat
Command-and-control (C2) domain - cdn[.]nerat[.]cc
C2 domain - connect[.]ne-rat[.]xyz
SSH key material - AAAAC3NzaC1lZDI1NTE5AAAAIP13pPAm5jmInLQYD3XNb3HwrW4cAKDcphoT4kSKrnte
Provider-reported account - proxyuser
Provider-reported SSH source - 193.32.127[.]248
Provider-reported IP and port - 31.77.220[.]138:2025
Provider-reported marker - /tmp/.vz_svc_done
Provider-reported SSH-key fingerprint - SHA256:YQmy1hKF1h5cdJLxlZ5EScNoxe/UDWahjsWuQw2ERi8
The Patch 9 release note said the Security Analyzer was added to release-candidate and stable branches. The incident advisory names the release Virtualizor 3.2.9.9 , while the release note calls it Virtualizor 3.2.9 (Release Candidate and Stable Branch) (Patch 9) . As of September 2, Virtualizor had not published a malicious-package filename or hash, an affected update-channel list, or a build that enforces package signing.
The scanner checks and contains known artifacts. Altered core Virtualizor files require restoration from known-good content or reinstallation. For a host with confirmed root compromise, the AlbaHost account said a clean rebuild is the only reliable long-term remediation.
Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/09/bgp-hijack-delivers-malicious.html