The server management panel Virtualizor recently suffered a devastating supply chain attack. Hackers maliciously manipulated Border Gateway Protocol (BGP) routing to redirect legitimate Virtualizor updates directly toward servers they controlled. Consequently, the attackers successfully installed backdoors onto host machines actively utilizing Virtualizor. They then injected their own SSH key pairs to guarantee total administrative control.
Preliminary investigations reveal a remarkably severe BGP hijacking incident. This complex attack directly involves Softaculous, the primary developer behind Virtualizor. It also involves Hetzner, a major German cloud computing provider. The attackers seemingly exploited configuration vulnerabilities within Hetzner’s Autonomous System Number (ASN) to effectively hijack the 162.55.80.0/24 subnet.
Overpowering Normal Routes via Specificity
This specific attack targeted the Hetzner 162.55.80.0/24 IP range. This critical subnet formally hosts Softaculous infrastructure, Virtualizor updates, and the customer service center. Normally, Hetzner proudly announces this specific range within the broader 162.55.0.0/16 prefix. However, AS62390/NexonHost illicitly announced the significantly more specific /24 route through AS6204/Zet.net.
Standard internet routing protocols inherently prioritize more specific prefixes. Therefore, networks receiving this fraudulent announcement naturally favored 162.55.80.0/24 over the legitimate 162.55.0.0/16 route. The clever hackers strategically retained the genuine Hetzner AS24940 at the very end of the AS path. This deceptive tactic made the abnormal route appear authentic rather than a blatant source AS impersonation. The exact method the hackers utilized to publish this illegal route through the Romanian NexonHost remains unclear. Investigators currently cannot determine if this involved a sophisticated attack or direct insider cooperation.
Bypassing TLS Certificate Verification
The most catastrophic element of this attack involved the simultaneous failure of crucial TLS protections. Primarily, Virtualizor software updates unfortunately lack an independent signature verification mechanism. The system relies entirely upon the domain’s TLS certificate for security validation. If the HTTPS connection throws no immediate errors, the system blindly downloads and installs the update.
Exploiting Let’s Encrypt Validation
Secondly, the BGP hijack successfully intercepted the specific network traffic Let’s Encrypt utilizes for domain control validation. Consequently, the attackers successfully passed the stringent verification process. They illicitly obtained a genuinely valid TLS certificate. Therefore, administrators executing updates through the Virtualizor panel never encountered any suspicious certificate errors. Ultimately, the attackers bypassed two critical security layers: correct IP routing and robust HTTPS server authentication.
Softaculous Struggles to Assess the Damage
Currently, the Softaculous corporation relies almost entirely upon direct administrator feedback to identify compromised servers. The company simply cannot provide a comprehensive list of affected machines. The attackers cleanly intercepted the relevant requests, completely bypassing the official server logs.
Therefore, VPS server providers utilizing this specific panel must independently investigate their own systems for anomalies. The hackers intentionally embedded destructive payloads via software updates and added unauthorized SSH key pairs. Administrators must thoroughly examine these specific vectors during their security audits.
Furthermore, the attack also compromised the primary Softaculous customer center. Users who logged into the customer center during the active hijacking period must immediately change their passwords. They must also rotate all API credentials, as these sensitive items may be exposed to the hackers. The critical hijacking window occurred between August 28, 2026, at 20:57 UTC, and August 30, 06:10 UTC.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!