Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Cybersecurity News
  5. BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Scheduled Pinned Locked Moved Cybersecurity News
1 Posts 1 Posters 4 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Virtualizor has disclosed that attackers abused a Border Gateway Protocol (BGP) hijack to intercept update traffic belonging to Softaculous, allowing them to distribute a malicious Virtualizor package to a subset of installations. The tampered update is reported to establish persistent root-level access on affected systems, marking a significant supply-chain incident for hosting providers relying on the platform.

    According to an account from a hosting provider, 5 out of 34 Virtualizor hypervisors that were checked showed signs of root-level compromise. The malicious activity is believed to have occurred within a specific window, beginning around August 28 at 20:57 (exact end time not disclosed).

    • The attack vector involved hijacking BGP routes to redirect Softaculous update traffic, rather than compromising the software repository directly.
    • The delivered payload targeted Virtualizor installations, with the goal of maintaining stealthy, persistent administrative access.
    • Hosting providers are advised to audit their Virtualizor hypervisors for unauthorized root access, especially if updates were applied during the incident window.

    Since the exact scope of affected installations is not yet confirmed, immediate steps for administrators include:

    • Reviewing system logs for any unauthorized SSH sessions or unexpected root-level commands during the specified timeframe.
    • Checking for newly created user accounts or modified SSH authorized_keys files.
    • Reinstalling or restoring Virtualizor from a verified, clean source if compromise is suspected.
    • Rotating all root and administrative credentials across affected and potentially affected systems.

    This incident underscores the risk inherent in relying on internet routing infrastructure for software updates, as a single BGP hijack can silently corrupt the trust chain of widely used management tools.

    Source: The Hacker News

    Has your team started auditing Virtualizor hypervisors for indicators of this attack, and what steps are you taking to verify the integrity of your current installations?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World