BGP hijack of Softaculous Virtualizor update prefix delivers malicious update granting root persistence
Attackers BGP-hijacked 162.55.80.0/24, the Softaculous Virtualizor update range, for roughly 33 hours (August 28 20:57 UTC to August 30 06:10 UTC, 2026) via AS62390 (NexonHost) through transit AS6204 (identified as Zet.net by Lobsters), forging Hetzner's…
Three reports describe a BGP hijack of 162.55.80.0/24, the prefix used by Softaculous' Virtualizor update service, between August 28 20:57 UTC and August 30 06:10 UTC, 2026 — a window of roughly 33 hours during which, per Ars Technica, the hijack pulsed intermittently and recurred twice, with routing described by Lobsters as fully restored afterward. AS62390 (NexonHost) announced the range without authorization via transit AS6204, retaining Hetzner's AS24940 on the AS path as the apparent origin; Ars notes the forged origin was nonetheless RPKI-valid and attributes the recurrence to lax routing configuration at Hetzner Online. The root cause is unconfirmed: Ars cites a possible compromise of Nexon Host (AS62390) infrastructure or of a customer. Because the Let's Encrypt CA's domain validation traffic was itself routed through the hijack (per Lobsters), the attacker obtained valid TLS certificates for virtualizor.com domains, so hijacked connections showed no TLS warnings. Virtualizor (via The Hacker News) says installations checking for updates during the window could receive a malicious package that added an attacker SSH key to root, created a proxyuser account, and installed a Java payload persisted via /etc/systemd/system/java-jre-update.service, with C2 domains cdn.nerat.cc and connect.ne-rat.xyz. AlbaHost confirmed 5 of its 34 Virtualizor hypervisors were root-compromised; Lobsters notes only Virtualizor has confirmed a malicious update, reaching 'a handful' of installations. Softaculous says only a small number of servers were likely affected but cannot produce a definitive list, urging administrators to treat every Virtualizor server as in scope; no affected-version range has been identified. RIPE RIS reconstruction found all 368 collector peers carried the hijacked route at some point, with roughly 28% time-weighted diversion. Virtualizor shipped Patch 9 with a Security Analyzer on September 1, 2026; cryptographic package signing remains future work. Experts cited by Ars called the routing lapses 'silly, preventable mistakes' avoidable with RPKI ROV and monitoring.
- Prefix hijacked: 162.55.80.0/24, used by Softaculous' Virtualizor update service.
- Incident window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC (~33 hours). Sources describe the hijack as pulsing intermittently within that window; Ars Technica says it recurred twice, while The Hacker News presents it as a…
- AS path: AS62390 (NexonHost) announced the prefix without authorization via transit AS6204 (identified as Zet.net by Lobsters), with Hetzner's AS24940 on the path as the apparent origin; Ars Technica describes the forged origin as…
- Ars Technica attributes the recurrence to lax routing configuration at Hetzner Online; the underlying cause of the unauthorized announcement (possible compromise of Nexon Host infrastructure or a customer) is unconfirmed.
- Attacker obtained valid Let's Encrypt certificates for virtualizor.com domains; Lobsters attributes this to the CA's domain validation being routed through the hijack, so affected connections showed no TLS warnings.
- Malicious update payload: added an attacker SSH key to root, created a proxyuser account, and installed a Java payload persisted via /etc/systemd/system/java-jre-update.service; C2 domains cdn.nerat.cc and connect.ne-rat.xyz (The Hacker…
- Confirmed impact: AlbaHost reported 5 of its 34 Virtualizor hypervisors root-compromised (The Hacker News); per Lobsters, only Virtualizor has confirmed a malicious update, which reached a handful of installations.
- Scope: Softaculous says only a small number of servers were likely affected but cannot produce a definitive list; no affected-version range has been identified; administrators are urged to treat every Virtualizor server as in scope for…
Coverage timelineoldest first · each row is one article
- · 13d agoBGP hijack infecting networks caused by a comedy of errors that’s not funny at all
Ars Technica · Security· 65
Attackers BGP-hijacked Softaculous IP space via Hetzner routing lapses to push malicious Virtualizor updates to hosting servers.