Hackers push malicious Virtualizor update in BGP hijacking attack

Refract AI Intelligence Digest

BLUF

Threat actors executed a BGP hijacking attack to distribute malware via legitimate Virtualizor software updates.

NEWS

Hackers intercepted and redirected update requests for Virtualizor VPS management software by manipulating Border Gateway Protocol routing tables. This allowed them to serve malicious payloads disguised as official patches to unsuspecting administrators. The incident exploits trust in network infrastructure rather than the software code itself.

Why I Care

This attack compromises the entire supply chain of VPS providers using Virtualizor, potentially granting attackers root access to thousands of virtual servers and undermining trust in automated update mechanisms.

Next Steps

Virtualizor users should immediately verify update signatures and check for unauthorized changes in their management panels. Network administrators must implement BGP route validation and monitor for anomalous routing announcements. Affected systems require credential rotation and forensic analysis by the end of the week.

Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
Back to Blog Listing

Source: BleepingComputer ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.