Hackers push malicious Virtualizor update in BGP hijacking attack
BLUF
Threat actors executed a BGP hijacking attack to distribute malware via legitimate Virtualizor software updates.
NEWS
Hackers intercepted and redirected update requests for Virtualizor VPS management software by manipulating Border Gateway Protocol routing tables. This allowed them to serve malicious payloads disguised as official patches to unsuspecting administrators. The incident exploits trust in network infrastructure rather than the software code itself.
Why I Care
This attack compromises the entire supply chain of VPS providers using Virtualizor, potentially granting attackers root access to thousands of virtual servers and undermining trust in automated update mechanisms.
Next Steps
Virtualizor users should immediately verify update signatures and check for unauthorized changes in their management panels. Network administrators must implement BGP route validation and monitor for anomalous routing announcements. Affected systems require credential rotation and forensic analysis by the end of the week.
Source: BleepingComputer ·