The veteran VPS server management panel Virtualizor has confirmed a serious supply-chain attack. Between 28 and 30 August 2026 UTC, attackers hijacked the BGP routing for the IP range hosting some Softaculous servers, diverting traffic bound for the management panel’s update servers to hosts under the attackers’ control.
Related discussion now also confirms that the host machines of several downstream VPS providers had backdoors implanted by the attackers. There is as yet no evidence that virtual machines on these hosts were poisoned, but users should immediately back up their server data to guard against encryption or theft.
A 33-Hour BGP Route Hijack
This supply-chain attack began at 20:57 UTC on 28 August 2026. The large-scale hijack actually unfolded in two waves, with roughly 11 hours of normal operation in between. According to an analysis of RIPE RIS data, all 368 observation peers saw the malicious route at some point. While the hijack was active, about 72% of the full set of RIS peers directed traffic to the attacker.
More seriously, the Let’s Encrypt validation requests for the relevant domains were likewise affected by the route hijack. The attacker could therefore obtain valid digital certificates for several Virtualizor-related domains outright. When downstream servers accessed the malicious update resources, no certificate error appeared, so reliance on HTTPS alone could not reveal the anomaly.
No Signature Verification and Escalation to Root
To this day, Virtualizor has not used strict signature verification when releasing updates. In other words, as long as a downstream server received an update (with no HTTPS error), it could install it directly. According to the current forensic findings, the attacker’s tampered package contained multiple pieces of malicious code, and the final payload was executed with root privileges.
The backdoor adds the attacker’s key pair to the host machine and downloads a Java-based persistence program, which then connects to 31.77.220.138:2025. Through the key pair, the attacker can log in to the server as root and carry out operations directly.
Many VPS Providers Use the Virtualizor Panel
A great many server providers use the Virtualizor management panel. Among them, AlbaHost has confirmed that five of its host machines were infected with the backdoor, though this provider’s audit has so far found no evidence of a database export. However, another VPS provider discovered signs suggesting a database may have been exported. Because the attacker had already gained root privileges, they could directly obtain passwords, database credentials, and other sensitive information on the affected nodes.
The Australian provider DreamIT Host was the first to notice the anomaly. The company issued an urgent warning on the LowEndTalk forum, urging all providers using the Virtualizor panel to investigate immediately. DreamIT Host has not yet disclosed whether any of its own hosts were affected.
VPS Providers Known to Use the Virtualizor Panel
Note: the following are providers that use the Virtualizor panel, but whether each was actually affected must be investigated and disclosed by the providers themselves. Very few have so far reported on the incident, and users are advised to back up their server data at once, in case ransomware is later deployed to encrypt files.
- SolidVPS
- SmokyHosts
- HostDare
- Fourplex
- RareCloud
- HostMayo
- HostNamaste
- LittleCreek
- HostSlick
- 3K33
- NaranjaTech
- iHostArt
The above is only a small selection; the number of platforms actually using this panel may run into the hundreds.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!