BGP Hijack of Softaculous Infrastructure Delivers Root-Persistent Malware via Malicious Virtualizor Update
A ~33-hour BGP hijack (2026-08-28 20:57 UTC to 2026-08-30 06:10 UTC) diverted Softaculous update traffic through AS62390 (NexonHost), letting attackers obtain valid Let's Encrypt certificates and push a malicious Virtualizor update that added an attacker SSH…
Between 2026-08-28 20:57 UTC and 2026-08-30 06:10 UTC (about 33 hours), attackers conducted an unauthorized BGP hijack of the Hetzner-hosted Softaculous IP block 162.55.80.0/24, diverting update traffic to an attacker-operated server. Per Lobsters' reconstruction from RIPE RIS data, AS62390 (NexonHost) announced the prefix via transit AS6204 (Zet.net) without authorization, retaining Hetzner's AS24940 on the AS path so Hetzner appeared to be the origin; all 368 RIPE RIS collector peers carried the hijacked route at some point, with roughly 28% time-weighted diversion. Because the Let's Encrypt CA's domain validation was also routed through the hijack, the attacker obtained valid certificates for virtualizor.com domains, so affected connections showed no TLS warnings. Virtualizor installations that checked for updates during the window could receive a malicious package that added an attacker SSH key to root, created a proxyuser account, and installed a Java payload persisted via the systemd service /etc/systemd/system/java-jre-update.service, with C2 domains cdn.nerat.cc and connect.ne-rat.xyz. No affected version range has been identified. Hosting provider AlbaHost confirmed 5 of its 34 Virtualizor hypervisors were root-compromised (The Hacker News); Lobsters notes that only Virtualizor has confirmed a malicious update via the channel, and all operators were urged to run checks. Routing was fully restored by the end of the window. Virtualizor shipped Patch 9 with a Security Analyzer on 2026-09-01, but cryptographic package signing remains future work. Operators are advised to run the official scanner, rotate API keys, and audit SSH keys, cron jobs, and users; client-area users who logged in or entered payment details during the window should reset passwords and review statements. The two sources agree on the incident window and mechanism: The Hacker News supplies precise timestamps and the AlbaHost impact figures, while Lobsters adds AS-path detail and RIPE RIS measurement figures; no material disagreements were identified.
- Incident window: 2026-08-28 20:57 UTC to 2026-08-30 06:10 UTC, approximately 33 hours (both sources consistent).
- AS62390 (NexonHost) announced 162.55.80.0/24 via transit AS6204 (Zet.net) without authorization, retaining Hetzner's AS24940 on the AS path so Hetzner appeared to be the origin.
- Attacker obtained valid Let's Encrypt certificates for virtualizor.com domains because CA domain validation was routed through the hijack; affected connections showed no TLS warnings.
- RIPE RIS reconstruction: all 368 collector peers carried the hijacked route at some point, with roughly 28% time-weighted diversion across the incident.
- Malicious Virtualizor update package added an attacker SSH key to root, created a proxyuser account, and installed a Java payload.
- Persistence mechanism: systemd service /etc/systemd/system/java-jre-update.service; C2 domains cdn.nerat.cc and connect.ne-rat.xyz.
- AlbaHost confirmed 5 of its 34 Virtualizor hypervisors were root-compromised (The Hacker News); per Lobsters, only Virtualizor has confirmed a malicious update via the channel.
- No affected Virtualizor version range has been identified.
Coverage timelineoldest first · each row is one article
- · 13d agoBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
The Hacker News· 74
Attackers used a BGP hijack to divert Softaculous traffic and push a malicious Virtualizor update granting root persistence on some hypervisors.